First published: Mon May 17 2021(Updated: )
IBM Security Access Manager Docker could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | =10.0.0 | |
Docker Docker | ||
<=10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
IBM Security Access Manager Docker vulnerability (CVE-2021-20511) allows a remote attacker to traverse directories on the system and view arbitrary files by sending a specially-crafted URL request containing dot dot sequences (/../).
The severity of IBM Security Access Manager Docker vulnerability (CVE-2021-20511) is medium with a severity value of 5.2.
IBM Security Access Manager Docker vulnerability (CVE-2021-20511) affects IBM Security Verify Access Docker 10.0.0 by allowing a remote attacker to traverse directories on the system.
An attacker can exploit IBM Security Access Manager Docker vulnerability (CVE-2021-20511) by sending a specially-crafted URL request with dot dot sequences (/../) to view arbitrary files on the system.
No, Docker itself is not vulnerable to IBM Security Access Manager Docker vulnerability (CVE-2021-20511).