| |
Vulnerability CVE-2016-2914
Published: 2016-08-07 Modified: 2016-08-08
Description: |
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension. |
CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5.5/10 |
4.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
Partial |
References: |
http://www-01.ibm.com/support/docview.wss?uid=swg21988263
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|