Directory Traversal Vulnerability in IBM Kenexa LMS on Cloud
CVE-2016-5941
5.7MEDIUM
Summary
IBM Kenexa LMS on Cloud is susceptible to a directory traversal vulnerability that enables remote attackers to exploit the system. By sending a specially crafted URL that contains dot dot sequences (/../), an attacker may gain unauthorized access to arbitrary files within the file system. This vulnerability poses a significant risk as it can lead to the exposure of sensitive information. Organizations utilizing this product should implement measures to mitigate potential threats and remediate the underlying issue.
Affected Version(s)
Kenexa LMS on Cloud 13.0
Kenexa LMS on Cloud 13.1
Kenexa LMS on Cloud 13.2
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved