CVE-2018-1797Path Traversal in IBM Websphere Application Server

CWE-22Path Traversal3 documents3 sources
Severity
5.5MEDIUMNVD
CNA6.3
EPSS
0.4%
top 37.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 13

Description

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/websphere_application_server7.0.0.07.0.0.45+3
CVEListV5ibm/websphere_application_server4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vm68-xcc6-2f3g: IBM WebSphere Application Server 72022-05-13
CVEList
CVE-2018-1797: IBM WebSphere Application Server 72018-11-16
CVE-2018-1797 — Path Traversal in IBM | cvebase