Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41296 | IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7167245 |
|
Fri, 06 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm webmethods Integration |
|
| CPEs | cpe:2.3:a:ibm:webmethods_integration:10.15:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm webmethods Integration |
Wed, 04 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Sep 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Title | IBM webMethods Integration directory traversal | |
| First Time appeared |
Softwareag
Softwareag webmethods |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:softwareag:webmethods:10.15:*:*:*:*:*:*:* | |
| Vendors & Products |
Softwareag
Softwareag webmethods |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-04T16:18:12.246Z
Reserved: 2024-08-21T19:10:49.905Z
Link: CVE-2024-45074
Updated: 2024-09-04T16:18:09.073Z
Status : Analyzed
Published: 2024-09-04T16:15:08.110
Modified: 2024-09-06T16:45:32.767
Link: CVE-2024-45074
No data.
OpenCVE Enrichment
No data.
EUVD