Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Pconsole_advisory | — | — | Dec 19, 2016 | Sep 26, 2016 |
| Aix 6.1.9 Pconsole_advisory | — | — | Dec 19, 2016 | Sep 26, 2016 |
| Aix 7.1.3 Pconsole_advisory | — | — | Dec 19, 2016 | Sep 26, 2016 |
| Ibm Aix | — | Apply the fix or workaround for pconsole_advisory | Nov 30, 2017 | Sep 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub