By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iseries_as_400 | Ibm | * | * |