CVE-2020-5016
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occur if Application security is enabled. IBM X-Force ID: 193556.
IBM WebSphere Application Server versiones 7.0, 8.0, 8.5 y 9.0, podría permitir a un atacante remoto saltos de directorios en el sistema. Cuando una seguridad de la aplicación está deshabilitada y unas aplicaciones JAX-RPC están presentes, un atacante podría enviar una petición de URL especialmente diseñada que contenga secuencias de "dot dot" (/../) para visualizar archivos xml arbitrarios en el sistema. Esto no ocurre si la seguridad de la aplicación está habilitada. IBM X-Force ID: 193556
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-30 CVE Reserved
- 2021-03-10 CVE Published
- 2024-09-17 CVE Updated
- 2024-11-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/pages/node/6427873 | 2021-03-17 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/193556 | 2021-03-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | >= 7.0.0.0 <= 7.0.0.45 Search vendor "Ibm" for product "Websphere Application Server" and version " >= 7.0.0.0 <= 7.0.0.45" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | >= 8.0.0.0 <= 8.0.0.15 Search vendor "Ibm" for product "Websphere Application Server" and version " >= 8.0.0.0 <= 8.0.0.15" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | >= 8.5.0.0 <= 8.5.5.19 Search vendor "Ibm" for product "Websphere Application Server" and version " >= 8.5.0.0 <= 8.5.5.19" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Websphere Application Server Search vendor "Ibm" for product "Websphere Application Server" | >= 9.0.0.0 <= 9.0.5.6 Search vendor "Ibm" for product "Websphere Application Server" and version " >= 9.0.0.0 <= 9.0.5.6" | - |
Affected
|