Логотип exploitDog
bind:CVE-2024-49780
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49780

Количество 3

Количество 3

nvd логотип

CVE-2024-49780

12 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-qj8v-rq4h-7fwh

12 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0  IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2025-06818

12 месяцев назад

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю записывать/перезаписывать произвольные файлы

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-49780

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-qj8v-rq4h-7fwh

IBM OpenPages with Watson 8.3 and 9.0  IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
fstec логотип
BDU:2025-06818

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю записывать/перезаписывать произвольные файлы

CVSS3: 5.3
0%
Низкий
12 месяцев назад

Уязвимостей на страницу