Home
MEDIUM: 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
2.0, 2.1, 2.2, 2.3
affected
Description
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
2.0, 2.1, 2.2, 2.3
References
www.ibm.com/support/pages/node/7234122