IBM Director CIM Server CIMListener Directory Traversal Vulnerability (Windows)

Summary
The host is running IBM Director CIM Server and is prone to directory traversal vulnerability.
Impact
Successful exploitation will allow remote attackers to traverse the file system and specify any library on the system. Impact Level: Application
Solution
Upgrade to IBM Director version 5.20.3 Service Update 2 or later, https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp&S_PKG=director_x_520&S_TACT=sms&lang=en_US&cp=UTF-8
Insight
The flaw is due to error in IBM Director CIM Server, which allow remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
Affected
IBM Director version 5.20.3 Service Update 1 and prior
References