Lucene search

K
ibmIBM296AAE8866503F613DADA2F687DE90E411F668FB156A26E6C2D7C628CC0A4211
HistoryJun 16, 2018 - 7:48 p.m.

Security Bulletin: IBM Tealeaf Customer Experience allows unauthorized access to system files (CVE-2015-4988)

2018-06-1619:48:28
www.ibm.com
7

0.003 Low

EPSS

Percentile

70.8%

Summary

The IBM Tealeaf Customer Experience replay server could allow an attacker to traverse directories and read any file on the Windows Server system hosting the server.

Vulnerability Details

CVEID: CVE-2015-4988**
DESCRIPTION:** The IBM Tealeaf Customer Experience replay server could allow an attacker to traverse directories and read any file on the Windows Server system hosting the server.
CVSS Base Score: 8.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105899 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)

Affected Products and Versions

IBM Tealeaf Customer Experience v8.0-v9.0.2

Remediation/Fixes

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM Tealeaf Customer Experience

|

9.0.2A

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.5168_9.0.2A_IBMTealeaf_CXUpgrade_FixPack2

IBM Tealeaf Customer Experience

|

9.0.2

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.1118_IBMTealeaf_CXUpgrade_FixPack2

IBM Tealeaf Customer Experience

|

9.0.1A

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.5091_9.0.1A_IBMTealeaf_CXUpgrade_FixPack4

IBM Tealeaf Customer Experience

|

9.0.1

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.1097_IBMTealeaf_CXUpgrade_FixPack4

IBM Tealeaf Customer Experience

|

9.0.0, 9.0.0A

| You can contact the Technical Support team for guidance.

IBM Tealeaf Customer Experience

|

8.8

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.8.0.9034_IBMTealeaf_CXUpgrade_FixPack8

IBM Tealeaf Customer Experience

|

8.7

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.7.1.8830_IBMTealeaf_CXUpgrade_FixPack9

IBM Tealeaf Customer Experience

|

8.6 and earlier

| You can contact the Technical Support team for guidance.
For v9.0.0, 9.0.0A, and versions before v8.7, IBM recommends upgrading to a later supported version of the product.

Workarounds and Mitigations

None

CPENameOperatorVersion
tealeaf customer experienceeqany

0.003 Low

EPSS

Percentile

70.8%

Related for 296AAE8866503F613DADA2F687DE90E411F668FB156A26E6C2D7C628CC0A4211