IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/155887 | VDB Entry Vendor Advisory |
http://www.ibm.com/support/docview.wss?uid=ibm10874666 | Vendor Advisory |
http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html |
Configurations
Information
Published : 2019-04-10 08:29
Updated : 2019-10-07 10:15
NVD link : CVE-2019-4013
Mitre link : CVE-2019-4013
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
ibm
- bigfix_platform