Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7rj-x62g-9rjj

Опубликовано: 24 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.

EPSS

Процентиль: 27%
0.00345
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость программной системы управления активами предприятия IBM Maximo Asset Management, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 27%
0.00345
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-98