Description
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-6522 | Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-06T17:46:22.839Z
Reserved: 2013-11-08T00:00:00.000Z
Link: CVE-2013-6720
No data.
Status : Modified
Published: 2014-03-06T11:55:05.100
Modified: 2026-05-06T22:30:45.220
Link: CVE-2013-6720
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD