Description
|
|
A vulnerability has been identified in IBM Tivoli Access Manager for e-Business, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error when handling certain character encodings on AIX, which could be exploited to conduct directory traversal attacks and disclose the contents of arbitrary files.
|
|
|
|
Vulnerable Products
|
|
Vulnerable Software: IBM Tivoli Access Manager for e-Business version 6.1.1 and prior
|
|
|
|
Solution
|
|
Apply patch 6.1.1-TIV-AWS-FP0001 :
http://www.ibm.com/support/fixcentral
|
|
|
|
CVE
|
|
CVE-2010-4623
CVE-2010-4622
|
|
|
|
References
|
|
http://www-01.ibm.com/support/docview.wss?uid=swg24028829
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
IPS Protection
|
|
|
|
|
|