CVE-2014-6194: Path Traversal
Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6194?
CVE-2014-6194 has been rated as a medium severity vulnerability, posing potential risks to sensitive data.
How do I fix CVE-2014-6194?
To fix CVE-2014-6194, ensure that your IBM Maximo Asset Management software is updated to versions 7.1.1.14 or 7.5.0.6 or later.
What type of vulnerability is CVE-2014-6194?
CVE-2014-6194 is classified as a directory traversal vulnerability.
Which software versions are affected by CVE-2014-6194?
CVE-2014-6194 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6.
What can happen if CVE-2014-6194 is exploited?
If exploited, CVE-2014-6194 may allow unauthorized users to access sensitive files on the server.