Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43rj-vhj3-86r7

Опубликовано: 22 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.

EPSS

Процентиль: 29%
0.00103
Низкий

8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8
nvd
около 2 лет назад

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.

EPSS

Процентиль: 29%
0.00103
Низкий

8 High

CVSS3

Дефекты

CWE-434