CVE-2021-20354: Path Traversal
Published Feb 18, 2021
·Updated
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Affected Software
10 affected components
IBM WebSphere Application Server>=8.0.0.0<=8.0.0.15
IBM WebSphere Application Server>=8.5.0.0<=8.5.5.19
IBM WebSphere Application Server>=9.0.0.0<=9.0.5.6
HP HP-UX
IBM AIX
IBM i
IBM Z\/os
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Feb 18, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20354?
The severity of CVE-2021-20354 is high, with a severity value of 7.5.
2
How does CVE-2021-20354 affect IBM WebSphere Application Server?
CVE-2021-20354 allows a remote attacker to traverse directories in IBM WebSphere Application Server 8.0, 8.5, and 9.0.
3
What can an attacker do with CVE-2021-20354?
An attacker can send a specially-crafted URL request to view arbitrary files on the system.
4
Which versions of IBM WebSphere Application Server are affected by CVE-2021-20354?
CVE-2021-20354 affects IBM WebSphere Application Server versions 8.0.0.0 to 8.0.0.15, 8.5.0.0 to 8.5.5.19, and 9.0.0.0 to 9.0.5.6.
5
How can I fix CVE-2021-20354?
To fix CVE-2021-20354, apply the necessary security patches provided by IBM.