Description
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.
Affected products
- IBM Corporation / Kenexa LMS on Cloud13.0 – 13.0
- IBM Corporation / Kenexa LMS on Cloud13.1 – 13.1
- IBM Corporation / Kenexa LMS on Cloud13.2 – 13.2
- IBM Corporation / Kenexa LMS on Cloud13.2.2 – 13.2.2
- IBM Corporation / Kenexa LMS on Cloud13.2.3 – 13.2.3
- IBM Corporation / Kenexa LMS on Cloud13.2.4 – 13.2.4
- IBM Corporation / Kenexa LMS on Cloud14.0.0 – 14.0.0
- IBM Corporation / Kenexa LMS on Cloud14.1.0 – 14.1.0
- IBM Corporation / Kenexa LMS on Cloud14.2.0 – 14.2.0