Description
|
|
A vulnerability has been identified in IBM Tivoli Access Manager for e-Business, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an unknown input validation error, which could be exploited to conduct directory traversal attacks and read the contents of arbitrary files.
|
|
|
|
Vulnerable Products
|
|
Vulnerable Software: IBM Tivoli Access Manager for e-Business version 6.1.0.5 and priorIBM Tivoli Access Manager for e-Business version 6.0.0.25 and priorIBM Tivoli Access Manager for e-Business version 5.1.0.39 and prior
|
|
|
|
Solution
|
|
Apply patches :
http://www-01.ibm.com/support/docview.wss?uid=swg21459999
|
|
|
|
CVE
|
|
CVE-2011-0494
|
|
|
|
References
|
|
http://www-01.ibm.com/support/docview.wss?uid=swg21459999
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
IPS Protection
|
|
|
|
|
|