CVE-2005-1244

Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netiq:pssecure:7.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:56

Type Values Removed Values Added
References () http://securitytracker.com/id?1013810 - Exploit, Vendor Advisory () http://securitytracker.com/id?1013810 - Exploit, Vendor Advisory
References () http://www.osvdb.org/15791 - () http://www.osvdb.org/15791 -
References () http://www.securityfocus.com/archive/1/396628 - Exploit () http://www.securityfocus.com/archive/1/396628 - Exploit
References () http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf - Exploit () http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/20260 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/20260 -

07 Nov 2023, 01:57

Type Values Removed Values Added
Summary ** DISPUTED ** Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable." Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this issue, saying that "neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.

Information

Published : 2005-04-20 04:00

Updated : 2024-11-20 23:56


NVD link : CVE-2005-1244

Mitre link : CVE-2005-1244

CVE.ORG link : CVE-2005-1244


JSON object : View

Products Affected

netiq

  • pssecure