Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.
| Software | From | Fixed in |
|---|---|---|
| sun / iplanet_directory_server | 5.0 | 5.0.x |
| sun / one_directory_server | 5.1-sp1 | 5.1-sp1.x |
| sun / one_directory_server | 5.1 | 5.1.x |
| sun / iplanet_directory_server | 5.1-sp2 | 5.1-sp2.x |
| sun / iplanet_directory_server | 5.1 | 5.1.x |
| sun / one_directory_server | 5.0_sp2 | 5.0_sp2.x |
| sun / one_directory_server | 5.0-sp1 | 5.0-sp1.x |
| sun / one_directory_server | 5.0 | 5.0.x |
| sun / iplanet_directory_server | 5.1-sp1 | 5.1-sp1.x |
| sun / one_directory_server | 5.1-sp2 | 5.1-sp2.x |