logo

Directory Traversal & File Retrieval Risks

ID: d8cb3ac6-adc9-57d0-ad0b-3e0f4f5c4342

STIX ID: report--d8cb3ac6-adc9-57d0-ad0b-3e0f4f5c4342

Feed Name: NCC Research

Threat Score
65/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

**Executive Summary:** This 2006 advisory from Virtual Security Research describes a directory traversal vulnerability in IBM Tivoli Access Manager's Web Server Plug-in (pkmslogout) that allows an authenticated attacker to read arbitrary files outside the web root (example: /etc/passwd). The report includes technical details, an exploitation example, vendor notification timeline, and links to IBM fix packs; administrators are advised to apply the provided fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.