CVE-2001-0982 Information

Description

Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing \2e\ strings.

Reference

ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README http://archives.neohapsis.com/archives/bugtraq/2001-07/0497.html http://www.osvdb.org/1908 http://www.securityfocus.com/bid/3080 http://www-1.ibm.com/support/search.wss?rs=0&q=IY18152&apar=only https://exchange.xforce.ibmcloud.com/vulnerabilities/6884

Share on: