Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jr6-qp52-8vfq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.

EPSS

Процентиль: 87%
0.03237
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 9 лет назад

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.

EPSS

Процентиль: 87%
0.03237
Низкий

7.2 High

CVSS3

Дефекты

CWE-434