IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html | |
http://www.ibm.com/support/docview.wss?uid=ibm10874666 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/155887 | VDB Entry Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-04-10 15:29
Updated : 2024-02-28 17:08
NVD link : CVE-2019-4013
Mitre link : CVE-2019-4013
CVE.ORG link : CVE-2019-4013
JSON object : View
Products Affected
ibm
- bigfix_platform
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type