>> CA Unicenter Web Services Distributed Management Directory Traversal Issue
Title : CA Unicenter Web Services Distributed Management Directory Traversal Issue VUPEN ID : VUPEN/ADV-2006-3873 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-03
Technical Description
A vulnerability has been identified in CA Unicenter Web Services Distributed Management, which could be exploited by remote attackers to gain unauthorized access to arbitrary files on a vulnerable system. This flaw is due to an input validation error in the embedded jetty java webserver when handling specially crafted HTTP requests (port 8282), which could be exploited by remote unauthenticated attackers to access and read the contents of arbitrary files.