CVE-2014-6155: Path Traversal
Multiple directory traversal vulnerabilities in the ServiceRegistry UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allow remote authenticated users to read arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6155?
CVE-2014-6155 is considered a high severity vulnerability due to its ability to allow remote authenticated users to access arbitrary files.
How do I fix CVE-2014-6155?
To mitigate CVE-2014-6155, upgrade your IBM WebSphere Service Registry and Repository to a patched version 8.0.0.3 or later, or 8.5.0.1 or later.
What versions of IBM WebSphere Service Registry and Repository are affected by CVE-2014-6155?
CVE-2014-6155 affects versions 7.5.x through 7.5.0.4, all 8.0.x versions prior to 8.0.0.3, and all 8.5.x versions prior to 8.5.0.1.
Can unauthenticated users exploit CVE-2014-6155?
No, CVE-2014-6155 can only be exploited by authenticated users of the IBM WebSphere Service Registry and Repository.
What must be done to secure systems against CVE-2014-6155?
To secure systems against CVE-2014-6155, ensure that your software is updated to the latest secure version and monitor for unauthorized access attempts.