CVE-2009-0880
12.03.2009, 15:20
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
| Vendor | Product | Version |
|---|---|---|
| ibm | director | 𝑥 ≤ 5.20.3 |
| ibm | director | 3.1.1 |
| ibm | director | 4.10 |
| ibm | director | 4.11 |
| ibm | director | 4.12 |
| ibm | director | 4.20 |
| ibm | director | 4.21 |
| ibm | director | 4.22 |
| ibm | director | 5.10.0 |
| ibm | director | 5.10.1 |
| ibm | director | 5.10.2 |
| ibm | director | 5.10.3 |
| ibm | director | 5.20.0 |
| ibm | director | 5.20.1 |
| ibm | director | 5.20.2 |
𝑥
= Vulnerable software versions
References