CVE-2016-1183

NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
nttdataterasoluna_server_framework_for_java_web
2.0.0.1
nttdataterasoluna_server_framework_for_java_web
2.0.0.2
nttdataterasoluna_server_framework_for_java_web
2.0.1.0
nttdataterasoluna_server_framework_for_java_web
2.0.2.0
nttdataterasoluna_server_framework_for_java_web
2.0.5.1
nttdataterasoluna_server_framework_for_java_web
2.0.5.2
nttdataterasoluna_server_framework_for_java_web
2.0.5.3
nttdataterasoluna_server_framework_for_java_web
2.0.6.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration