CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 268751.
Configurations

No configuration.

History

21 Nov 2024, 08:26

Type Values Removed Values Added
Summary
  • (es) IBM Engineering Lifecycle Optimization Publishing 7.0.2 y 7.03 podría permitir a un atacante remoto cargar archivos arbitrarios, provocados por la validación inadecuada de las extensiones de archivo. Al enviar una solicitud especialmente manipulada, un atacante remoto podría aprovechar esta vulnerabilidad para cargar un archivo malicioso, lo que podría permitirle ejecutar código arbitrario en el sistema vulnerable. ID de IBM X-Force: 268751.
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/268751 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/268751 -
References () https://www.ibm.com/support/pages/node/7156757 - () https://www.ibm.com/support/pages/node/7156757 -

09 Jun 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-09 13:15

Updated : 2024-11-21 08:26


NVD link : CVE-2023-45188

Mitre link : CVE-2023-45188

CVE.ORG link : CVE-2023-45188


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type