Unrated severityNVD Advisory· Published Apr 16, 2007· Updated Apr 23, 2026
CVE-2007-2048
CVE-2007-2048
Description
Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.
Affected products
3cpe:2.3:a:webmethods:glue:4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:webmethods:glue:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:webmethods:glue:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:webmethods:glue:6.5.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.aushack.com/advisories/200704-webmethods.txtnvdExploit
- www.securityfocus.com/bid/23423nvdExploit
- secunia.com/advisories/24933nvd
- securityreason.com/securityalert/2589nvd
- www.securityfocus.com/archive/1/465332/100/0/threadednvd
- www.securityfocus.com/archive/1/465993/100/0/threadednvd
- www.securityfocus.com/archive/1/467873/30/6720/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/1363nvd
News mentions
0No linked articles in our index yet.