CVE Vulnerabilities

CVE-2016-1183

Published: Jun 19, 2016 | Modified: Apr 12, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.

Affected Software

NameVendorStart VersionEnd Version
Terasoluna_server_framework_for_java_webNttdata2.0.0.1 (including)2.0.0.1 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.0.2 (including)2.0.0.2 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.1.0 (including)2.0.1.0 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.2.0 (including)2.0.2.0 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.5.1 (including)2.0.5.1 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.5.2 (including)2.0.5.2 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.5.3 (including)2.0.5.3 (including)
Terasoluna_server_framework_for_java_webNttdata2.0.6.1 (including)2.0.6.1 (including)

References