CVE-2024-49780
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.
Vendor
Product
CWE
Yayın Tarihi
2025-02-20 04:15:10
Güncelleme
2025-03-11 14:37:00
Source Identifier
psirt@us.ibm.com
KEV Date Added
-