Race Condition Vulnerability in IBM System Networking Switch Center and Lenovo Switch Center
CVE-2015-7820

Currently unrated

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
12 November 2015

Summary

A race condition vulnerability exists in the administration-panel web service of IBM System Networking Switch Center and Lenovo Switch Center. When exploited, remote attackers can gain privileged-account access by sending specially crafted requests to specific ports. This weakness allows the attacker to use directory traversal sequences in ZipDownload.jsp input, enabling them to read arbitrary files on the affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.