IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
| Software | From | Fixed in |
|---|---|---|
| ibm / tivoli_monitoring | 6.3.0.7 | 6.3.0.7.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp1 | 6.3.0.7-sp1.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp10 | 6.3.0.7-sp10.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp11 | 6.3.0.7-sp11.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp12 | 6.3.0.7-sp12.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp13 | 6.3.0.7-sp13.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp14 | 6.3.0.7-sp14.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp15 | 6.3.0.7-sp15.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp16 | 6.3.0.7-sp16.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp17 | 6.3.0.7-sp17.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp18 | 6.3.0.7-sp18.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp19 | 6.3.0.7-sp19.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp2 | 6.3.0.7-sp2.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp20 | 6.3.0.7-sp20.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp21 | 6.3.0.7-sp21.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp3 | 6.3.0.7-sp3.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp4 | 6.3.0.7-sp4.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp5 | 6.3.0.7-sp5.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp6 | 6.3.0.7-sp6.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp7 | 6.3.0.7-sp7.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp8 | 6.3.0.7-sp8.x |
| ibm / tivoli_monitoring | 6.3.0.7-sp9 | 6.3.0.7-sp9.x |