IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1034103 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21964828 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV71196 | vendor advisory |