First published: Sun Nov 08 2015(Updated: )
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Web | =7.0 | |
IBM Security Access Manager for Web | =7.0.0.1 | |
IBM Security Access Manager for Web | =7.0.0.2 | |
IBM Security Access Manager for Web | =7.0.0.3 | |
IBM Security Access Manager for Web | =7.0.0.4 | |
IBM Security Access Manager for Web | =7.0.0.5 | |
IBM Security Access Manager for Web | =7.0.0.6 | |
IBM Security Access Manager for Web | =7.0.0.7 | |
IBM Security Access Manager for Web | =7.0.0.8 | |
IBM Security Access Manager for Web | =7.0.0.9 | |
IBM Security Access Manager for Web | =7.0.0.10 | |
IBM Security Access Manager for Web | =7.0.0.11 | |
IBM Security Access Manager for Web | =7.0.0.12 | |
IBM Security Access Manager for Web | =7.0.0.13 | |
IBM Security Access Manager for Web | =7.0.0.14 | |
IBM Security Access Manager for Web | =7.0.0.15 | |
IBM Security Access Manager for Web | =8.0 | |
IBM Security Access Manager for Web | =8.0.0.2 | |
IBM Security Access Manager for Web | =8.0.0.3 | |
IBM Security Access Manager for Web | =8.0.0.4 | |
IBM Security Access Manager for Web | =8.0.0.5 | |
IBM Security Access Manager for Web | =8.0.0.22 | |
IBM Security Access Manager for Web | =8.0.0.31 | |
IBM Security Access Manager for Web | =8.0.1.0 | |
IBM Security Access Manager for Web | =8.0.1.1 | |
IBM Security Access Manager for Web | =8.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.