CVE-2014-6158: Path Traversal
Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3) Emergency Fixes component.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6158?
The severity of CVE-2014-6158 is classified as high due to the potential for remote code execution.
How do I fix CVE-2014-6158?
To fix CVE-2014-6158, update IBM PureApplication System to versions 1.0.0.4 or later, 1.1.0.5 or later, or 2.0.0.1 or later.
Who is affected by CVE-2014-6158?
CVE-2014-6158 affects users of IBM PureApplication System 1.0.0.0 to 1.0.0.3, 1.1.0.0 to 1.1.0.4, and IBM Workload Deployer 3.1.0.7.
What type of vulnerability is CVE-2014-6158?
CVE-2014-6158 is a directory traversal vulnerability in the file-upload feature.
What can attackers achieve with CVE-2014-6158?
Attackers can potentially execute arbitrary code on the affected systems if they exploit CVE-2014-6158.