SB2023011823 - Path traversal in IBM Tivoli System Automation Application Manager
Published: January 18, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2018-1797)
The vulnerability allows a remote attacker to conduct directory traversal attack.
The vulnerability exists due to improper validation of user-supplied input on systems that have an Enterprise Bundle Archive (EBA) installed and with a path external to the EBA. A remote attacker can trick the victim into extracting a specially crafted ZIP archive containing 'dot dot slash' sequences that, when executed, will write arbitrary files on the target system.
Note: This vulnerability is known as "Zip-Slip".
Remediation
Install update from vendor's website.