MEDIUM · 4.0

CVE-2010-0154

Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote au...

Vulnerability Description

Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmProventia Network Mail Security System Virtual ApplianceAll versions
IbmProventia Network Mail Security System Virtual Appliance Firmware1.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0154?

CVE-2010-0154 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote au...

How severe is CVE-2010-0154?

CVE-2010-0154 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0154?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Proventia Network Mail Security System Virtual Appliance, Ibm Proventia Network Mail Security System Virtual Appliance Firmware.