First published: Mon Feb 01 2021(Updated: )
IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 191752.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =3.0.0 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=3.0CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4934 is a vulnerability in IBM Content Navigator that allows a remote attacker to traverse directories on the system.
An attacker can send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
IBM Content Navigator version 3.0.CD is affected by CVE-2020-4934.
CVE-2020-4934 has a severity rating of 4.3, which is considered medium.
IBM has released patches and updates to fix CVE-2020-4934, so make sure to update to the latest version of IBM Content Navigator.