CVE-2024-41765: IBM Engineering Lifecycle Optimization - Publishing directory traversal
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
IBM Engineering Lifecycle Optimization - Publishing could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41765?
CVE-2024-41765 has a high severity rating due to its potential to allow remote directory traversal attacks.
How do I fix CVE-2024-41765?
To fix CVE-2024-41765, upgrade IBM Engineering Lifecycle Optimization - Publishing to version 7.0.4 or later.
What versions are affected by CVE-2024-41765?
CVE-2024-41765 affects IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3.
What type of vulnerability is CVE-2024-41765?
CVE-2024-41765 is a directory traversal vulnerability allowing unauthorized access to files on the system.
Can CVE-2024-41765 be exploited remotely?
Yes, CVE-2024-41765 can be exploited remotely by sending specially crafted URL requests.