IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HIBM Bigfix Platform
APPIbm9.5.0 – 9.5.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References
Related vulnerabilities
CVE-2018-1475CRITICAL9.8PL ✓same product
IBM BigFix Platform — brute force kont przez brak blokady logowania
CVE-2017-1221CRITICAL9.8PL ✓same product
IBM BigFix: brak wymogu silnych haseł umożliwia przejęcie kont
CVE-2016-6082CRITICAL10.0PL ✓same product
RCE przez use-after-free race condition w IBM BigFix Platform
CVE-2018-1600HIGH8.6same product
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication...
CVE-2018-1479HIGH8.8same product
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to e...