CVE-2005-1238

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2005
Last modified:
03/04/2025

Description

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:ibm:iseries_as_400:*:*:*:*:*:*:*:*