CVE-2009-0880
12.03.2009, 15:20
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
Vendor | Product | Version |
---|---|---|
ibm | director | 𝑥 ≤ 5.20.3 |
ibm | director | 3.1.1 |
ibm | director | 4.10 |
ibm | director | 4.11 |
ibm | director | 4.12 |
ibm | director | 4.20 |
ibm | director | 4.21 |
ibm | director | 4.22 |
ibm | director | 5.10.0 |
ibm | director | 5.10.1 |
ibm | director | 5.10.2 |
ibm | director | 5.10.3 |
ibm | director | 5.20.0 |
ibm | director | 5.20.1 |
ibm | director | 5.20.2 |
𝑥
= Vulnerable software versions
References