Arbitrary File Read Vulnerability in NTT Data TERASOLUNA Server Framework for Java

Arbitrary File Read Vulnerability in NTT Data TERASOLUNA Server Framework for Java

CVE-2016-1183 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.

Learn more about our Web App Pen Testing.