Directory Traversal Vulnerability in IBM Engineering Lifecycle Optimization
CVE-2024-41765
6.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 January 2025
What is CVE-2024-41765?
A directory traversal vulnerability exists in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This issue enables remote attackers to exploit specially crafted URL requests containing 'dot dot' sequences (/../). By doing so, attackers gain unauthorized access to arbitrary files within the system, potentially exposing sensitive information. It highlights the need for stringent input validation and proper access controls to mitigate such threats and safeguard sensitive data.
Affected Version(s)
Engineering Lifecycle Optimization Publishing 7.0.2, 7.0.3