Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.
| Software | From | Fixed in |
|---|---|---|
| ibm / tivoli_secureway_policy_director | 3.0.1 | 3.0.1.x |
| ibm / tivoli_secureway_policy_director | 3.7 | 3.7.x |
| ibm / tivoli_secureway_policy_director | 3.6 | 3.6.x |
| ibm / tivoli_secureway_policy_director | 3.7.1 | 3.7.1.x |