Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Spectrum Protect Operations Center HIGH 8.0
CVE-2020-4955

IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter…

Fix: 7.1.13.000 / 8.1.10.200+
Fix from $1,950 2021-02-15
Cloud Pak System MEDIUM 6.7
CVE-2020-4928

IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent…

Fix: 2.3.3.3+
Fix from $1,600 2021-01-04
I2 Ibase HIGH 7.8
CVE-2020-4588

IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code …

Fix: after 8.9.13
Fix from $1,950 2020-10-30
Data Risk Manager HIGH 8.8
CVE-2020-4620EPSS 5%

IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Spectrum Protect Plus HIGH 8.0
CVE-2020-4703

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.6
Fix from $1,950 2020-09-15
Spectrum Protect Plus HIGH 8.0
CVE-2020-4470

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be…

Fix: after 10.1.5
Fix from $1,950 2020-06-15
Planning Analytics HIGH 8.8
CVE-2019-4612

IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici…

Mitigation only
Fix from $1,950 2019-12-09
Cloud Pak System HIGH 8.8
CVE-2019-4130

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod…

Patch available
Fix from $1,950 2019-12-03
Security Guardium HIGH 8.8
CVE-2019-4292

IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the v…

Patch available
Fix from $1,950 2019-07-02
Intelligent Operations Center HIGH 8.8
CVE-2019-4069

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. …

Fix: after 5.2.1.1
Fix from $1,950 2019-06-07
Bigfix Platform CRITICAL 9.9
CVE-2019-4013EPSS 14%

IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod…

Fix: after 9.5.11
Fix from $2,300 2019-04-10
Security Identity Manager CRITICAL 9.9
CVE-2018-1969

IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the…

Fix: after 6.0.0.20
Fix from $2,300 2019-01-14
Robotic Process Automation With Automation Anywhere HIGH 8.8
CVE-2018-1552

IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a m…

Patch available
Fix from $1,950 2018-11-02
Security Identity Manager HIGH 8.8
CVE-2018-1453

IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be autom…

Patch available
Fix from $1,950 2018-06-08
Maximo Asset Management HIGH 8.8
CVE-2017-1499

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary…

Patch available
Fix from $1,950 2018-02-14
Sametime MEDIUM 5.5
CVE-2016-0354

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co…

Patch available
Fix from $1,600 2017-08-29
Security Key Lifecycle Manager HIGH 7.2
CVE-2016-6104

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file exte…

Patch available
Fix from $1,950 2017-02-07
Kenexa Lms On Cloud HIGH 8.8
CVE-2016-6124

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb…

Mitigation only
Fix from $1,950 2017-02-01
Filenet Workplace Xt HIGH 8.8
CVE-2016-8921

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul…

Mitigation only
Fix from $1,950 2017-02-01
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2016-2914

Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authe…

Patch available
Fix from $1,600 2016-08-08