Lucene search

K
cve[email protected]CVE-2015-7817
HistoryNov 12, 2015 - 3:59 a.m.

CVE-2015-7817

2015-11-1203:59:05
CWE-362
web.nvd.nist.gov
22
cve-2015-7817
race condition
ibm system networking switch center
lenovo switch center
privileged account access
filereader.jsp
directory traversal
arbitrary text files
remote attackers

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.225 Low

EPSS

Percentile

96.5%

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read arbitrary text files, via a request to port 40080 or 40443.

Affected configurations

NVD
Node
ibmsystem_networking_switch_centerRange7.3.1.4
Node
lenovoswitch_centerRange8.1.1.0

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.225 Low

EPSS

Percentile

96.5%

Related for CVE-2015-7817