The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
References
Link | Resource |
---|---|
https://support.lenovo.com/us/en/product_security/len_2015_074 | Vendor Advisory |
http://www.zerodayinitiative.com/advisories/ZDI-15-551/ |
Information
Published : 2015-11-11 19:59
Updated : 2015-11-12 11:04
NVD link : CVE-2015-7818
Mitre link : CVE-2015-7818
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
lenovo
- switch_center
ibm
- system_networking_switch_center