Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-42017

Опубликовано: 22 дек. 2023
Источник: nvd
CVSS3: 8
CVSS3: 9.8
EPSS Низкий

Описание

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:planning_analytics:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00092
Низкий

8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8
github
около 2 лет назад

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.

EPSS

Процентиль: 27%
0.00092
Низкий

8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434