Directory Traversal & File Retrieval Risks
ID: d8cb3ac6-adc9-57d0-ad0b-3e0f4f5c4342
STIX ID: report--d8cb3ac6-adc9-57d0-ad0b-3e0f4f5c4342
Feed Name: NCC Research
Threat Score
**Executive Summary:** This 2006 advisory from Virtual Security Research describes a directory traversal vulnerability in IBM Tivoli Access Manager's Web Server Plug-in (pkmslogout) that allows an authenticated attacker to read arbitrary files outside the web root (example: /etc/passwd). The report includes technical details, an exploitation example, vendor notification timeline, and links to IBM fix packs; administrators are advised to apply the provided fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
