CVE-2016-1183
Last modified
CVE-2016-1183 is a vulnerability of currently unknown severity. NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.0.1 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.0.2 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.1.0 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.2.0 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.5.1 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.5.2 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.5.3 |
| Nttdata | Terasoluna Server Framework For Java Web | 2.0.6.1 |
References
- http://jvn.jp/en/jp/JVN74659077/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000098Vendor Advisory
- http://jvn.jp/en/jp/JVN74659077/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000098Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1183?
How severe is CVE-2016-1183?
How do I fix CVE-2016-1183?
Are you affected by CVE-2016-1183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
