The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iseries_as_400 | Ibm | 4.3 (including) | 4.3 (including) |