First published: Sun Jun 07 2015(Updated: )
Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Marketing Operations | =7.2.0.0 | |
IBM Marketing Operations | =7.2.0.4 | |
IBM Marketing Operations | =7.2.1.0 | |
IBM Marketing Operations | =7.2.1.12 | |
IBM Marketing Operations | =7.3.2.0 | |
IBM Marketing Operations | =7.3.2.1 | |
IBM Marketing Operations | =7.3.2.8 | |
IBM Marketing Operations | =7.4.0.0 | |
IBM Marketing Operations | =7.4.0.2 | |
IBM Marketing Operations | =7.4.1.0 | |
IBM Marketing Operations | =7.4.1.6 | |
IBM Marketing Operations | =7.4.2.0 | |
IBM Marketing Operations | =7.4.2.7 | |
IBM Marketing Operations | =7.5.0.0 | |
IBM Marketing Operations | =7.5.0.1 | |
IBM Marketing Operations | =7.5.2.0 | |
IBM Marketing Operations | =7.5.2.3 | |
IBM Marketing Operations | =7.5.3.0 | |
IBM Marketing Operations | =7.5.3.7 | |
IBM Marketing Operations | =7.5.3.8 | |
IBM Marketing Operations | =7.5.3.9 | |
IBM Marketing Operations | =8.0.0.0 | |
IBM Marketing Operations | =8.0.0.2 | |
IBM Marketing Operations | =8.1.0.0 | |
IBM Marketing Operations | =8.1.0.6 | |
IBM Marketing Operations | =8.1.0.7 | |
IBM Marketing Operations | =8.1.1.0 | |
IBM Marketing Operations | =8.1.1.4 | |
IBM Marketing Operations | =8.2.0.0 | |
IBM Marketing Operations | =8.2.0.5 | |
IBM Marketing Operations | =8.2.0.6 | |
IBM Marketing Operations | =8.2.0.7 | |
IBM Marketing Operations | =8.2.0.8 | |
IBM Marketing Operations | =8.2.0.9 | |
IBM Marketing Operations | =8.2.0.10 | |
IBM Marketing Operations | =8.2.0.11 | |
IBM Marketing Operations | =8.2.0.12 | |
IBM Marketing Operations | =8.2.0.13 | |
IBM Marketing Operations | =8.5.0.0 | |
IBM Marketing Operations | =8.5.0.1 | |
IBM Marketing Operations | =8.5.0.2 | |
IBM Marketing Operations | =8.5.0.3 | |
IBM Marketing Operations | =8.5.0.4 | |
IBM Marketing Operations | =8.5.0.5 | |
IBM Marketing Operations | =8.5.0.6 | |
IBM Marketing Operations | =8.5.0.7 | |
IBM Marketing Operations | =8.6.0.0 | |
IBM Marketing Operations | =8.6.0.2 | |
IBM Marketing Operations | =8.6.0.3 | |
IBM Marketing Operations | =8.6.0.4 | |
IBM Marketing Operations | =8.6.0.5 | |
IBM Marketing Operations | =8.6.0.6 | |
IBM Marketing Operations | =8.6.0.7 | |
IBM Marketing Operations | =9.0.0.0 | |
IBM Marketing Operations | =9.0.0.1 | |
IBM Marketing Operations | =9.0.0.2 | |
IBM Marketing Operations | =9.0.0.3 | |
IBM Marketing Operations | =9.0.0.4 | |
IBM Marketing Operations | =9.1.0.0 | |
IBM Marketing Operations | =9.1.0.2 | |
IBM Marketing Operations | =9.1.0.3 | |
IBM Marketing Operations | =9.1.0.4 | |
IBM Marketing Operations | =9.1.1.0 | |
IBM Marketing Operations | =9.1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-6222 is classified as high due to its potential to allow unauthorized access to arbitrary files.
To fix CVE-2014-6222, update IBM Marketing Operations to the versions that address the vulnerability as specified in the advisory.
CVE-2014-6222 affects IBM Marketing Operations versions 7.x, 8.x, 9.0.x, 9.1.0.x and others as listed in the advisory.
CVE-2014-6222 is a directory traversal vulnerability that can be exploited by remote authenticated users.
An attacker could exploit CVE-2014-6222 to read arbitrary files from the server, potentially leading to further compromise.