Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj8v-rq4h-7fwh

Опубликовано: 20 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

IBM OpenPages with Watson 8.3 and 9.0 

IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

IBM OpenPages with Watson 8.3 and 9.0 

IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

CVSS3: 5.3
fstec
12 месяцев назад

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю записывать/перезаписывать произвольные файлы

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22