Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Ruby on Rails affects IBM Endpoint Manager for Security Configuration Management (CVE-2014-7829)

   
Affected software IBM
 
Ruby on Rails could allow a remote attacker to obtain sensitive information, caused by an information leak in Action Pack. By sending a specially crafted request, a remote attacker could exploit this vulnerability to determine if a file exists on the filesystem outside the applications root directory. CVE(s): CVE-2014-7829 Affected product(s) and affected version(s): IBM Endpoint Manager for Security Configuration Management – Security Configuration Analysis Component (IEM for

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ruby_on_rails_affects_ibm_endpoint_manager_for_security_configuration_management_cve_2014_7829?lang=en_us