CVE-2021-20517

CVSS v3 Score
6.4
Medium
CVSS v2 Score
6.5
Medium

Vulnerability Description

IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435.

CVSS:6.4(Medium)

Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.

CWE-222015
CVSS:6.4(Medium)

Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers. The directory path access check of the internal flash file system can be ...

CWE-222020
CVSS:6.4(Medium)

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file inclu...

CWE-222024
CVSS:6.4(Medium)

In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.

CWE-222025
CVSS:6.5(Medium)

Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (...

CWE-222009