First published: Wed Jun 29 2016(Updated: )
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | <=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0298 has a medium severity level due to its directory traversal nature.
To fix CVE-2016-0298, upgrade IBM Security Guardium Database Activity Monitor to version 10.0p100 or later.
CVE-2016-0298 is a directory traversal vulnerability that allows remote authenticated users to access arbitrary files.
IBM Security Guardium Database Activity Monitor versions before 10.0p100 are affected by CVE-2016-0298.
Yes, CVE-2016-0298 can be exploited remotely by authenticated users via a crafted URL.