First published: Mon Feb 03 2020(Updated: )
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | =7.0.1 | |
<=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4674 is a vulnerability in IBM Security Identity Manager 7.0.1 that allows a remote attacker to traverse directories on the system and view arbitrary files.
CVE-2019-4674 works by exploiting a flaw in IBM Security Identity Manager 7.0.1 that allows an attacker to send a specially-crafted URL request containing "dot dot" sequences to view arbitrary files on the system.
CVE-2019-4674 has a severity rating of 6.8 (medium).
To fix CVE-2019-4674, it is recommended to upgrade to a version of IBM Security Identity Manager that is not affected by this vulnerability or apply the necessary patches provided by IBM.
More information about CVE-2019-4674 can be found on the IBM X-Force Exchange website and the IBM support pages.