Directory Traversal Vulnerability in IBM Campaign Software
CVE-2019-4384
4.3MEDIUM
What is CVE-2019-4384?
IBM Campaign versions 9.1.2 and 10.1 are susceptible to a directory traversal vulnerability that enables remote attackers to manipulate URL requests. By crafting a request that includes 'dot dot' sequences, an attacker can potentially access and view arbitrary files on the system, leading to unauthorized access to sensitive data. It is essential for users to apply security patches and implement appropriate access controls to mitigate this risk.
Affected Version(s)
Campaign 9.1.2
Campaign 10.1