#VU15918 Path traversal in IBM WebSphere Application Server - CVE-2018-1797
Published: November 15, 2018 / Updated: November 16, 2018
IBM WebSphere Application Server
IBM Corporation
Description
The vulnerability allows a remote attacker to conduct directory traversal attack.
The vulnerability exists due to improper validation of user-supplied input on systems that have an Enterprise Bundle Archive (EBA) installed and with a path external to the EBA. A remote attacker can trick the victim into extracting a specially crafted ZIP archive containing 'dot dot slash' sequences that, when executed, will write arbitrary files on the target system.
Note: This vulnerability is known as "Zip-Slip".