Lucene search

K
cveMitreCVE-2009-0880
HistoryMar 12, 2009 - 3:20 p.m.

CVE-2009-0880

2009-03-1215:20:49
CWE-22
mitre
web.nvd.nist.gov
45
ibm director
cve-2009-0880
directory traversal
cim server
windows
vulnerability
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.405

Percentile

97.3%

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a … (dot dot) in a /CIMListener/ URI in an M-POST request.

Affected configurations

Nvd
Node
ibmdirectorRange5.20.3service_update_1
OR
ibmdirectorMatch3.1.1
OR
ibmdirectorMatch4.10
OR
ibmdirectorMatch4.11
OR
ibmdirectorMatch4.12
OR
ibmdirectorMatch4.20
OR
ibmdirectorMatch4.21
OR
ibmdirectorMatch4.22
OR
ibmdirectorMatch5.10.0
OR
ibmdirectorMatch5.10.1
OR
ibmdirectorMatch5.10.2
OR
ibmdirectorMatch5.10.3
OR
ibmdirectorMatch5.20.0
OR
ibmdirectorMatch5.20.1
OR
ibmdirectorMatch5.20.2
AND
microsoftwindows
VendorProductVersionCPE
ibmdirector*cpe:2.3:a:ibm:director:*:service_update_1:*:*:*:*:*:*
ibmdirector3.1.1cpe:2.3:a:ibm:director:3.1.1:*:*:*:*:*:*:*
ibmdirector4.10cpe:2.3:a:ibm:director:4.10:*:*:*:*:*:*:*
ibmdirector4.11cpe:2.3:a:ibm:director:4.11:*:*:*:*:*:*:*
ibmdirector4.12cpe:2.3:a:ibm:director:4.12:*:*:*:*:*:*:*
ibmdirector4.20cpe:2.3:a:ibm:director:4.20:*:*:*:*:*:*:*
ibmdirector4.21cpe:2.3:a:ibm:director:4.21:*:*:*:*:*:*:*
ibmdirector4.22cpe:2.3:a:ibm:director:4.22:*:*:*:*:*:*:*
ibmdirector5.10.0cpe:2.3:a:ibm:director:5.10.0:*:*:*:*:*:*:*
ibmdirector5.10.1cpe:2.3:a:ibm:director:5.10.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.405

Percentile

97.3%