CVE-2009-0880

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
ibmdirector
𝑥
≤ 5.20.3
ibmdirector
3.1.1
ibmdirector
4.10
ibmdirector
4.11
ibmdirector
4.12
ibmdirector
4.20
ibmdirector
4.21
ibmdirector
4.22
ibmdirector
5.10.0
ibmdirector
5.10.1
ibmdirector
5.10.2
ibmdirector
5.10.3
ibmdirector
5.20.0
ibmdirector
5.20.1
ibmdirector
5.20.2
𝑥
= Vulnerable software versions