CVE-2019-4430: Path Traversal
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4430?
CVE-2019-4430 is considered a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2019-4430?
To fix CVE-2019-4430, apply the latest security patches provided by IBM for Maximo Asset Management version 7.6.
What systems are affected by CVE-2019-4430?
CVE-2019-4430 specifically affects IBM Maximo Asset Management version 7.6.
Can CVE-2019-4430 be exploited remotely?
Yes, CVE-2019-4430 allows for remote exploitation by sending specially-crafted URL requests.
What could an attacker achieve with CVE-2019-4430?
An attacker exploiting CVE-2019-4430 could traverse directories and potentially view arbitrary files on the system.