Vulnerability Description
Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Directory Server | 6.2.0 |
| Ibm | Security Directory Server | 6.4.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21986452Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21986452Vendor Advisory
FAQ
What is CVE-2015-1977?
CVE-2015-1977 is a vulnerability with a CVSS score of 7.5 (HIGH). Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43...
How severe is CVE-2015-1977?
CVE-2015-1977 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1977?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tivoli Directory Server, Ibm Security Directory Server.