NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.0.1 (including) | 2.0.0.1 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.0.2 (including) | 2.0.0.2 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.1.0 (including) | 2.0.1.0 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.2.0 (including) | 2.0.2.0 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.5.1 (including) | 2.0.5.1 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.5.2 (including) | 2.0.5.2 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.5.3 (including) | 2.0.5.3 (including) |
Terasoluna_server_framework_for_java_web | Nttdata | 2.0.6.1 (including) | 2.0.6.1 (including) |