CVE-2013-6720
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 28.58% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ibm/tealeaf cx
- Source
- psirt@us.ibm.com
References
- http://www.exploit-db.com/exploits/32546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89229
- https://tealeaf.support.ibmcloud.com/FileManagement/Download/19eb90ffb8334b398684b4350edc4b7aVendor Advisory
- http://www.exploit-db.com/exploits/32546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89229
- https://tealeaf.support.ibmcloud.com/FileManagement/Download/19eb90ffb8334b398684b4350edc4b7aVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.