PT-2019-16911 · Ibm · Ibm Cloud Pak System

Published

2019-12-03

·

Updated

2019-12-09

·

CVE-2019-4130

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak System versions 2.3 through 2.3.0.1
Description The issue allows a remote attacker to upload arbitrary files, potentially enabling the execution of arbitrary code on the vulnerable server.
Recommendations For IBM Cloud Pak System versions 2.3 through 2.3.0.1, update to a version that contains a fix for this issue to prevent arbitrary file uploads and potential code execution.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4130

Affected Products

Ibm Cloud Pak System