| Vulnerability Name: | CVE-2006-0513 (CCN-24485) | ||||||||
| Assigned: | 2006-02-03 | ||||||||
| Published: | 2006-02-03 | ||||||||
| Updated: | 2018-10-19 | ||||||||
| Summary: | Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | ||||||||
| CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
6.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Feb 03 2006 - 17:39:57 CST VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability Source: MITRE Type: CNA CVE-2006-0513 Source: FULLDISC Type: UNKNOWN 20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability Source: CCN Type: SA18725 IBM Tivoli Access Manager for e-business "pkmslogout" Directory Traversal Source: SECUNIA Type: Patch, Vendor Advisory 18725 Source: SREASON Type: UNKNOWN 412 Source: CCN Type: SECTRACK ID: 1015582 IBM Tivoli Access Manager Input Validation Hole in Web Server Plug-in `pkmslogout` Script Lets Remote Authenticated Users Traverse the Directory Source: SECTRACK Type: Exploit, Patch 1015582 Source: AIXAPAR Type: Patch IY79724 Source: CCN Type: IBM Support Web site Tivoli Access Manager Plug-in for Web Servers 5.1 Fix Pack 5.1.0-TIV-WPI-FP0017 Source: CCN Type: OSVDB ID: 22933 IBM Tivoli Access Manager for e-business pkmslogout filename Parameter Traversal Arbitrary File Access Source: BUGTRAQ Type: UNKNOWN 20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability Source: BID Type: UNKNOWN 16494 Source: CCN Type: BID-16494 IBM Tivoli Access Manager Plugin Directory Traversal Vulnerability Source: CCN Type: Virtual Security Research, LLC. Security Advisory 2006-02-03 Remote Directory Traversal and File Retrieval Source: MISC Type: Exploit, Patch, Vendor Advisory http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt Source: VUPEN Type: UNKNOWN ADV-2006-0442 Source: XF Type: UNKNOWN tivoli-pkmslogout-directory-traversal(24485) Source: XF Type: UNKNOWN tivoli-pkmslogout-directory-traversal(24485) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||