Directory traversal vulnerability in the Admin Center for Tivoli Storage...
Vulnerability Description
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot dot) in the query parameter in a writeDataFile action to the fileRequestor servlet, execute arbitrary files via a .. (dot dot) in the query parameter in a (2) run or (3) runClear action to the fileRequestor servlet, (4) read arbitrary files via a readDataFile action to the fileRequestor servlet, (5) execute arbitrary code via a save_server_groups action to the userRequest servlet, or (6) delete arbitrary files via a del action in the fileRequestServlet servlet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3914
Credits & Attribution
No credits recorded in the NVD database.
References
- http://zerodayinitiative.com/advisories/ZDI-14-166/
- http://www.exploit-db.com/exploits/33807
- http://zerodayinitiative.com/advisories/ZDI-14-165/
- http://zerodayinitiative.com/advisories/ZDI-14-163/
- http://zerodayinitiative.com/advisories/ZDI-14-161/
- http://zerodayinitiative.com/advisories/ZDI-14-162/
More from rocketsoftware
View All →Affected Vendor
rocketsoftware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.