First published: Thu Feb 29 2024(Updated: )
IBM Content Navigator could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet Content Manager | <=5.5.8 | |
IBM FileNet Content Manager | <=5.5.10 | |
IBM FileNet Content Manager | <=5.5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38366 has been classified with a severity that indicates a significant risk of directory traversal.
To address CVE-2023-38366, apply the latest security patches provided by IBM for the affected versions of FileNet Content Manager.
CVE-2023-38366 affects IBM FileNet Content Manager versions up to 5.5.10.
Yes, CVE-2023-38366 can be exploited remotely through specially crafted URLs that utilize directory traversal techniques.
Exploitation of CVE-2023-38366 can allow unauthorized access to arbitrary files on the system, risking sensitive data exposure.