First published: Mon Feb 16 2015(Updated: )
Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a ZIP archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lexmark Markvision Enterprise |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9375 is classified as a medium severity vulnerability due to its potential for unauthorized file access and execution.
To mitigate CVE-2014-9375, update Lexmark Markvision Enterprise to the latest version that includes security patches addressing this vulnerability.
CVE-2014-9375 affects authenticated users of Lexmark Markvision Enterprise who can exploit the directory traversal vulnerability.
CVE-2014-9375 is a directory traversal vulnerability that allows remote authenticated users to manipulate file paths in ZIP archives.
An attacker could exploit CVE-2014-9375 to write and execute arbitrary files on the server, potentially compromising the system.