Path traversal in IBM WebSphere Application Server - CVE-2018-1770
Published: October 16, 2018
IBM WebSphere Application Server
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the Admin Console interface. A remote authenticated user can send a specially crafted HTTP request and read arbitrary files on the system.
How to mitigate CVE-2018-1770
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH01617
--OR--
· Apply Fix Pack 9.0.0.10 or later (targeted availability 4Q2018).
For V8.5.0.0 through 8.5.5.14:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH01617
--OR--
· Apply Fix Pack 8.5.5.15 or later (targeted availability 1Q2019).
For V8.0.0.0 through 8.0.0.15:
· Upgrade to a minimal fix pack levels as required by interim fix and then apply Interim Fix PH01617
For V7.0.0.0 through 7.0.0.45:
· Upgrade to a minimal fix pack levels as required by interim fix and then apply Interim Fix PH01617