Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-12376 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427. |
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-17T02:15:38.311Z
Reserved: 2017-12-13T00:00:00.000Z
Link: CVE-2018-1797
No data.
Status : Modified
Published: 2018-11-16T15:29:00.347
Modified: 2026-06-17T01:51:47.730
Link: CVE-2018-1797
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
EUVD