F5 Data Manager Multiple Directory Traversal Vulnerabilities
Description
Multiple vulnerabilities have been identified in F5 Data Manager, which could be exploited by malicious users to gain knowledge of sensitive information. These issues are caused by input validation errors in the "acopia/manager/DiagLogListActionBody.do", "acopia/manager/DiagCaptureFileListActionBody.do", "acopia/sat/ViewSatReport.do", "acopia/manager/DiagCaptureFileListActionBody.do" and "acopia/sat/ViewInventoryErrorReport.do" scripts when processing the "logFile", "captureFile", "fileName" and "capture" parameters, which could be exploited by malicious administrators to download arbitrary files from a vulnerable system via directory traversal attacks.
Vulnerable Products
Vulnerable Software: F5 Data Manager version 2.06 and prior