Path Traversal Vulnerability in IBM Java Runtime Environment Diagnostic Tooling Framework
CVE-2018-1656

7.4HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 August 2018

Summary

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) is susceptible to path traversal attacks when handling compressed dump files. This vulnerability allows attackers to potentially write arbitrary files outside the intended directory, leading to unauthorized data access and modification. Users of affected versions are advised to implement necessary security updates to mitigate potential risks.

Affected Version(s)

SDK, Java Technology Edition 6.0

SDK, Java Technology Edition 7.0

SDK, Java Technology Edition 8.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.