peter bassill · operator
$ cve CVE-2010-2655 JSON

CVE-2010-2655 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS2.29% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2010-07-08
Last modified2026-06-16

Affected (2)

VendorProduct
ibmadvanced management module
ibmbladecenter

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD