PT-2014-3933 · Ibm · Ibm Security Appscan Standard
Publicado
2014-03-26
·
Atualizado
2017-08-29
·
CVE-2014-0904
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Security AppScan Standard versions 7.9 through 8.8
Description
The update process does not require integrity checks of downloaded files, allowing remote attackers to execute arbitrary code via a crafted file.
Recommendations
For IBM Security AppScan Standard versions 7.9 through 8.8, update the software to a version that includes integrity checks for downloaded files to prevent arbitrary code execution.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Security Appscan Standard