Directory Traversal Vulnerability in IBM Kenexa LMS on Cloud
CVE-2016-5941

5.7MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM Kenexa LMS on Cloud is susceptible to a directory traversal vulnerability that enables remote attackers to exploit the system. By sending a specially crafted URL that contains dot dot sequences (/../), an attacker may gain unauthorized access to arbitrary files within the file system. This vulnerability poses a significant risk as it can lead to the exposure of sensitive information. Organizations utilizing this product should implement measures to mitigate potential threats and remediate the underlying issue.

Affected Version(s)

Kenexa LMS on Cloud 13.0

Kenexa LMS on Cloud 13.1

Kenexa LMS on Cloud 13.2

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.