Path traversal in MySQL Enterprise Monitor - CVE-2016-9878
Published: April 20, 2018
Vulnerability identifier: #VU12008
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9878
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a physical authenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper sanitization of paths provided to the ResourceServlet. A physical attacker can trigger path traversal and gain access to potentially sensitive information.
The weakness exists due to improper sanitization of paths provided to the ResourceServlet. A physical attacker can trigger path traversal and gain access to potentially sensitive information.
Affected software
MySQL Enterprise Monitor
Fedora
springframework
IBM Engineering Requirements Management DOORS Next
IBM Cognos Controller
Fedora
springframework
IBM Engineering Requirements Management DOORS Next
IBM Cognos Controller
How to mitigate CVE-2016-9878
Install update from vendor's website.
springframework - update to 3.2.18-1.fc25
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2