Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2015-11-12T02:00:00
Updated: 2024-08-06T07:58:59.953Z
Reserved: 2015-10-14T00:00:00
Link: CVE-2015-7817
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-11-12T03:59:05.170
Modified: 2024-11-21T02:37:27.613
Link: CVE-2015-7817
Redhat
No data.