Vulnerability Bulletins

IBM Security Bulletin: IBM Endpoint Manager for Software Use Analysis v9 and v2.2 are vulnerable to two attacks on Ruby on Rails component - CVE-2014-0130, CVE-2014-7829

   
Affected software IBM
 
IBM Endpoint Manager for Software Use Analysis v9 and v2.2 is vulnerable to two exploits related to Ruby on Rails framework. Ruby on Rails handles, among others, network communications of the IBM Endpoint Manager for Software Use Analysis server. CVE-2014-0130 allows an unauthorized attacker to read any file from the machine that is hosting IBM Endpoint Manager for Software Use Analysis server, using a specially prepared HTTP request. CVE-2014-7829 allows an unauthorizes attacker to determine,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_endpoint_manager_for_software_use_analysis_v9_and_v2_2_are_vulnerable_to_two_attacks_on_ruby_on_rails_component_cve_2014_0130_cve_2014_7829?lang=en_us