First published: Thu May 27 2021(Updated: )
IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server ND | <=9.0 | |
IBM WebSphere Application Server ND | <=8.5 | |
IBM WebSphere Application Server ND | >=8.5.0.0<8.5.5.20 | |
IBM WebSphere Application Server ND | >=9.0.0.0<9.0.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20517 is a vulnerability in IBM WebSphere Application Server Network Deployment 8.5 and 9.0 that allows a remote authenticated attacker to traverse directories and read/delete arbitrary files on the system.
CVE-2021-20517 has a severity rating of 8.8, which is considered high.
CVE-2021-20517 allows a remote authenticated attacker to traverse directories and potentially read/delete arbitrary files on IBM WebSphere Application Server ND 8.5 and 9.0.
The IBM X-Force ID for CVE-2021-20517 is 198435.
To fix the CVE-2021-20517 vulnerability, it is recommended to apply the necessary patches provided by IBM and ensure the affected versions of IBM WebSphere Application Server ND are updated to the latest version.