The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
References
Link | Resource |
---|---|
http://www.zerodayinitiative.com/advisories/ZDI-15-551/ | |
https://support.lenovo.com/us/en/product_security/len_2015_074 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2015-11-12T02:00:00
Updated: 2015-11-12T02:57:01
Reserved: 2015-10-14T00:00:00
Link: CVE-2015-7818
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-11-12T03:59:06.500
Modified: 2015-11-12T19:04:48.440
Link: CVE-2015-7818
JSON object: View
Redhat Information
No data.
CWE