Vulnerability Bulletins |
IBM Security Bulletin: WEB FORM DOES NOT PROPERLY VALIDATE CLIENT-SUPPLIED INPUT (CVE-2014-6194) |
|
| Affected software | IBM |
|
IBM Maximo Asset Management could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request "dot dot" sequences (/../) to view arbitrary files on the system. CVE(s): CVE-2014-6194 Affected product(s) and affected version(s): 1. Maximo Asset Management 7.5, 7.1 2. Maximo Asset Management Essentials 7.5, 7.1 3. Maximo for Government 7.5, 7.1 4. Maximo for Nuclear Power 7.5, 7.1 5. Maximo for Transportation 7.5, 7.1 More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_web_form_does_not_properly_validate_client_supplied_input_cve_2014_6194?lang=en_us |
|






