IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 159883.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
Rational Collaborative Lifecycle Management
Subscribe
Rational Doors Next Generation
Subscribe
Rational Engineering Lifecycle Manager
Subscribe
Rational Quality Manager
Subscribe
Rational Rhapsody Design Manager
Subscribe
Rational Software Architect Design Manager
Subscribe
Rational Team Concert
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13859 | IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 159883. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T18:23:47.067Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-4252
No data.
Status : Modified
Published: 2019-06-27T14:15:10.737
Modified: 2024-11-21T04:43:22.770
Link: CVE-2019-4252
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD