CVE-2011-4135
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-1389.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 30.17% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- flexerasoftware/flexnet publisher
- Source
- cve@mitre.org
References
- http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Q200975&sliceId=1Vendor Advisory
- http://secunia.com/advisories/45615Vendor Advisory
- http://www.flexerasoftware.com/pl/13057.htmPatch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21577760
- http://www.securityfocus.com/bid/49191
- http://www.zerodayinitiative.com/advisories/ZDI-11-272/
- http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Q200975&sliceId=1Vendor Advisory
- http://secunia.com/advisories/45615Vendor Advisory
- http://www.flexerasoftware.com/pl/13057.htmPatch, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21577760
- http://www.securityfocus.com/bid/49191
- http://www.zerodayinitiative.com/advisories/ZDI-11-272/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.