Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-1389


Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.


Published

2012-01-19T19:55:00.990

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm rational_license_key_server 8.0 Yes
Application ibm rational_license_key_server 8.1 Yes
Application ibm rational_license_key_server 8.1.1 Yes
Application ibm rational_license_key_server 8.1.2 Yes
Application ibm rational_license_server 7.0 Yes
Application ibm rational_license_server 7.1 Yes
Application ibm rational_license_server 7.5 Yes
Application ibm telelogic_license_server 2.0 Yes

References