Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38902 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7180201 |
|
Fri, 21 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm engineering Lifecycle Optimization Publishing
Linux Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:7.0.2:-:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:7.0.3:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm engineering Lifecycle Optimization Publishing
Linux Linux linux Kernel Microsoft Microsoft windows |
Mon, 06 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Jan 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Title | IBM Engineering Lifecycle Optimization - Publishing directory traversal | |
| First Time appeared |
Ibm
Ibm engineering Lifecycle Optimization - Publishing |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_publishing:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_publishing:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm engineering Lifecycle Optimization - Publishing |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-06T16:01:44.609Z
Reserved: 2024-07-22T12:02:49.316Z
Link: CVE-2024-41765
Updated: 2025-01-06T16:01:40.270Z
Status : Analyzed
Published: 2025-01-04T15:15:06.713
Modified: 2025-03-21T14:13:55.840
Link: CVE-2024-41765
No data.
OpenCVE Enrichment
No data.
EUVD