Description
IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 268751.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49495 | IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 268751. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-02T20:14:19.731Z
Reserved: 2023-10-05T01:39:10.397Z
Link: CVE-2023-45188
Updated: 2024-08-02T20:14:19.731Z
Status : Awaiting Analysis
Published: 2024-06-09T13:15:49.537
Modified: 2024-11-21T08:26:30.613
Link: CVE-2023-45188
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD