The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/88179 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=1011824 | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-1448.html | vendor advisory |