Vulnerability CVE-2019-4442


Published: 2019-09-17

Description:
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Vendor: IBM
Product: Websphere application server 
Version:
9.0.5.1
9.0.5.0
9.0.0.9
9.0.0.8
9.0.0.7
9.0.0.6
9.0.0.5
9.0.0.4
9.0.0.3
9.0.0.2
9.0.0.11
9.0.0.10
9.0.0.1
9.0.0.0
8.5.5.9
8.5.5.8
8.5.5.7
8.5.5.6
8.5.5.5
8.5.5.4
8.5.5.3
8.5.5.2
8.5.5.16
8.5.5.15
8.5.5.14
8.5.5.13
8.5.5.12
8.5.5.11
8.5.5.10
8.5.5.1
8.5.5.0
8.5.0.2
8.5.0.1
8.5.0.0
8.0.0.9
8.0.0.8
8.0.0.7
8.0.0.6
8.0.0.5
8.0.0.4
8.0.0.3
8.0.0.2
8.0.0.15
8.0.0.14
8.0.0.13
8.0.0.12
8.0.0.11
8.0.0.10
8.0.0.1
8.0.0.0
7.0.0.9
7.0.0.8
7.0.0.7
7.0.0.6
7.0.0.5
7.0.0.45
7.0.0.43
7.0.0.41
7.0.0.4
7.0.0.39
7.0.0.38
7.0.0.37
7.0.0.36
7.0.0.35
7.0.0.34
7.0.0.33
7.0.0.32
7.0.0.31
7.0.0.3
7.0.0.29
7.0.0.27
7.0.0.25
7.0.0.24
7.0.0.23
7.0.0.22
7.0.0.21
7.0.0.2
7.0.0.19
7.0.0.18
7.0.0.17
7.0.0.16
7.0.0.15
7.0.0.14
7.0.0.13
7.0.0.12
7.0.0.11
7.0.0.10
7.0.0.1
7.0.0.0

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/163226
https://www.ibm.com/support/pages/node/959021

Related CVE
CVE-2019-4265
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.
CVE-2019-4558
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setui...
CVE-2019-4512
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
CVE-2019-4564
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2019-4514
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165136.
CVE-2019-4227
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
CVE-2019-4441
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
CVE-2019-4422
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.

Copyright 2019, cxsecurity.com

 

Back to Top