
CVE-2011-1376
https://notcve.org/view.php?id=CVE-2011-1376
19 Jan 2012 — iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations. iscdeploy en IBM WebSphere Application Server (WAS) v6.1 antes de v6.1.0.43, v7.0 antes de v7.0.0.21 y v8.0 antes de v8.0.0.2 en la plataforma IBM i establece permisos débiles bajo systemApps/isclite.ear y /bin/cli... • http://www-01.ibm.com/support/docview.wss?uid=swg21569205 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-1359
https://notcve.org/view.php?id=CVE-2011-1359
06 Sep 2011 — Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. Vulnerabilidad de salto de directorio en la consola de administración en IBM WebSphere Application Server (WAS) v6.1 anteriores a v6.1.0.41, v7.0 anteriores a v7.0.0.19, y v8.0 anteriores a v8.0.0.1, permite a atacantes remotos leer ficheros locales de su elecci... • http://secunia.com/advisories/45749 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •