CVE-2012-4834 Information

Description

Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.

Reference

http://secunia.com/advisories/51281 http://www.ibm.com/connections/blogs/PSIRT/entry/security_vulnerability_in_theme_component_for_websphere_portal_versions_7_0_0_x_and_8_0_cve2012_48344 http://www.ibm.com/support/docview.wss?uid=swg21617713 http://www.ibm.com/support/docview.wss?uid=swg24033155 http://www-01.ibm.com/support/docview.wss?uid=swg1PM76354 https://exchange.xforce.ibmcloud.com/vulnerabilities/78914

Share on: