2015-11-12 04:59:08 2015-11-12 19:46:25

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before and Lenovo Switch Center before allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.