CVE-2024-45074: IBM webMethods Integration directory traversal
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
IBM webMethods Integration could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45074?
CVE-2024-45074 has a medium severity rating due to its potential for directory traversal by authenticated users.
How do I fix CVE-2024-45074?
To fix CVE-2024-45074, ensure you apply the latest security patches from IBM for webMethods Integration 10.15.
What systems are affected by CVE-2024-45074?
CVE-2024-45074 affects IBM webMethods Integration version 10.15 and earlier.
Can CVE-2024-45074 be exploited remotely?
CVE-2024-45074 requires an authenticated user to exploit the vulnerability through specially crafted URL requests.
What vulnerabilities does CVE-2024-45074 allow attackers to exploit?
CVE-2024-45074 allows attackers to potentially access arbitrary files on the system through directory traversal.