MEDIUM🇵🇱 Wersja polska

CVE-2023-43044

CVSS 5.3v3.1pub. 2023-09-28upd. 2024-11-21

IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266893.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • IBM License Metric Tool

    APP
    Ibm
    < 9.2.33
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2016-8964CRITICAL9.8PL ✓same product

IBM BigFix Inventory: niewystarczające blokowanie konta umożliwia atak brute force

CVE-2016-8980HIGH8.1same product

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)...

CVE-2025-36352MEDIUM6.4same product

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability ...

CVE-2025-36351MEDIUM4.3same product

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in ...

CVE-2016-8961MEDIUM6.1same product

IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect atta...