Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bmc
Bmc compuware Istrobe Web |
|
| Vendors & Products |
Bmc
Bmc compuware Istrobe Web |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint. | |
| Title | Compuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:08:43.216Z
Reserved: 2025-12-11T00:58:28.456Z
Link: CVE-2024-58298
Updated: 2025-12-15T19:27:23.394Z
Status : Deferred
Published: 2025-12-11T22:15:51.060
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-58298
No data.
OpenCVE Enrichment
Updated: 2025-12-12T08:49:53Z