IBM Tivoli Lightweight Client Framework信息泄露漏洞

漏洞信息详情

IBM Tivoli Lightweight Client Framework信息泄露漏洞

漏洞简介

IBM Tivoli Management Framework 3.7.1版本中Tivoli Lightweight Client Framework (LCF)的HTTP界面在安装的时候设置http_disable为零,远程验证用户可以借助记录文件的未明操作绕过Tivoli Endpoint Configuration数据文件上的文件权限。

漏洞公告

The vendor has released an advisory along with configuration parameters to resolve this issue. Please see the referenced advisory for further information.

参考网址

来源: XF
名称: tivoli-lcf-file-read(3927)
链接:http://xforce.iss.net/xforce/xfdb/3927

来源: BID
名称: 17085
链接:http://www.securityfocus.com/bid/17085

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享