CVE ID | CVE-2015-7817 |
CVSS SCORE | 7.1, AV:N/AC:M/Au:N/C:C/I:N/A:N |
AFFECTED VENDORS |
IBM |
AFFECTED PRODUCTS |
System Networking Switch Center |
VULNERABILITY DETAILS |
The specific flaws exist within the IBM SNSC Web Service, which listens by default on ports 40080 (HTTP) or 40443 (HTTPS) for requests to the administration panel. The first is a race condition, which allows the for the temporary use of a fixed privileged account which is forbidden from interactive login, and the second is a directory traversal vulnerability in FileReader.jsp. By combining these two vulnerabilities, an attacker can read arbitrary text files on the system. |
ADDITIONAL DETAILS |
IBM has issued an update to correct this vulnerability. More details can be found at:
https://support.lenovo.com/us/en/product_security/len_2015_074 |
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi (rgod) |