UNIX symbolic link following in Apache Commons FileUpload - CVE-2013-0248
Published: July 19, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue. The application uses the /tmp directory for uploaded files. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
Gentoo Linux
IBM App Connect for Healthcare
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Integration Designer
How to mitigate CVE-2013-0248
IBM Tivoli Business Service Manager - update to 6.2.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.2.0.2
External References
Related Security Bulletins
- Symbolic link following in Apache Commons FileUpload
- Gentoo update for Apache Commons FileUpload
- Symbolic link following in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM App Connect for Healthcare
- Multiple vulnerabilities in IBM Integration Designer
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager