CVE-2019-4674: Path Traversal
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
Other sources
IBM Security Identity Manager could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4674?
CVE-2019-4674 is a vulnerability in IBM Security Identity Manager 7.0.1 that allows a remote attacker to traverse directories on the system and view arbitrary files.
How does CVE-2019-4674 work?
CVE-2019-4674 works by exploiting a flaw in IBM Security Identity Manager 7.0.1 that allows an attacker to send a specially-crafted URL request containing "dot dot" sequences to view arbitrary files on the system.
What is the severity of CVE-2019-4674?
CVE-2019-4674 has a severity rating of 6.8 (medium).
How do I fix CVE-2019-4674?
To fix CVE-2019-4674, it is recommended to upgrade to a version of IBM Security Identity Manager that is not affected by this vulnerability or apply the necessary patches provided by IBM.
Where can I find more information about CVE-2019-4674?
More information about CVE-2019-4674 can be found on the IBM X-Force Exchange website and the IBM support pages.