CVE-2012-2206 Information
Feb 14, 2021
cve
Description
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
Reference
http://www.exploit-db.com/exploits/20478/ http://www.ibm.com/support/docview.wss?uid=swg21607481 http://www-01.ibm.com/support/docview.wss?uid=swg1IC82761 https://exchange.xforce.ibmcloud.com/vulnerabilities/77095
Share on: