Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request. Per: http://www.securityfocus.com/archive/1/archive/1/501639/100/0/threaded
"The vendor has adressed this vulnerability in service update 2 for IBM
Director agent 5.20.3. Download link:
https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?sourcedmp
&S_PKGdirector_x_520&S_TACTsms<en_US&cpUTF-8"
Publication date: Thu, 12 Mar 2009 20:20:00 +0000