First published: Wed Sep 18 2019(Updated: )
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) v2.0.0.0 through 2.0.0.5, v2.1.0.0 through 2.1.0.4, v2.1.1.0 through 2.1.1.4, and v3.0.0.0 through 3.0.0.8 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 150946.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager For Multiplatform | >=2.0.0.0<=2.0.0.5 | |
Ibm Financial Transaction Manager For Multiplatform | >=2.1.0.0<=2.1.0.4 | |
Ibm Financial Transaction Manager For Multiplatform | >=2.1.1.0<=2.1.1.4 | |
Ibm Financial Transaction Manager For Multiplatform | >=3.0.0.0<=3.0.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1847 is medium with a severity value of 6.5.
A remote attacker can exploit CVE-2018-1847 by sending a specially-crafted URL request containing directory traversal sequences.
IBM Financial Transaction Manager for Multi-Platform versions 2.0.0.0 through 2.0.0.5, 2.1.0.0 through 2.1.0.4, 2.1.1.0 through 2.1.1.4, and 3.0.0.0 through 3.0.0.8 are affected by CVE-2018-1847.
Yes, there are fixes available for CVE-2018-1847. Please refer to the IBM support pages for more information.
The CWE ID for CVE-2018-1847 is CWE-22.