Vulnerability index

Browse CVEs

50 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.0 CVE-2020-4955 IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter… Spectrum Protect Operations Center 7.1.13.000 / 8.1.10.200+ Fix from $1,9502021-02-15 MEDIUM 6.7 CVE-2020-4928 IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent… Cloud Pak System 2.3.3.3+ Fix from $1,6002021-01-04 HIGH 7.8 CVE-2020-4588 IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code … I2 Ibase after 8.9.13 Fix from $1,9502020-10-30 HIGH 8.8 CVE-2020-4620EPSS 5% IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 8.0 CVE-2020-4703 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be… Spectrum Protect Plus after 10.1.6 Fix from $1,9502020-09-15 HIGH 8.0 CVE-2020-4470 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-06-15 HIGH 8.8 CVE-2019-4612 IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malici… Planning Analytics Mitigation only Fix from $1,9502019-12-09 HIGH 8.8 CVE-2019-4130 IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary cod… Cloud Pak System Patch available Fix from $1,9502019-12-03 HIGH 8.8 CVE-2019-4292 IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the v… Security Guardium Patch available Fix from $1,9502019-07-02 HIGH 8.8 CVE-2019-4069 IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. … Intelligent Operations Center after 5.2.1.1 Fix from $1,9502019-06-07 CRITICAL 9.9 CVE-2019-4013EPSS 14% IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in cod… Bigfix Platform after 9.5.11 Fix from $2,3002019-04-10 CRITICAL 9.9 CVE-2018-1969 IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the… Security Identity Manager after 6.0.0.20 Fix from $2,3002019-01-14 HIGH 8.8 CVE-2018-1552 IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a m… Robotic Process Automation With Automation Anywhere Patch available Fix from $1,9502018-11-02 HIGH 8.8 CVE-2018-1453 IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be autom… Security Identity Manager Patch available Fix from $1,9502018-06-08 HIGH 8.8 CVE-2017-1499 IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary… Maximo Asset Management Patch available Fix from $1,9502018-02-14 MEDIUM 5.5 CVE-2016-0354 IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co… Sametime Patch available Fix from $1,6002017-08-29 HIGH 7.2 CVE-2016-6104 IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file exte… Security Key Lifecycle Manager Patch available Fix from $1,9502017-02-07 HIGH 8.8 CVE-2016-6124 IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb… Kenexa Lms On Cloud Mitigation only Fix from $1,9502017-02-01 HIGH 8.8 CVE-2016-8921 IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul… Filenet Workplace Xt Mitigation only Fix from $1,9502017-02-01 MEDIUM 5.4 CVE-2016-2914 Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authe… Engineering Lifecycle Optimization Publishing Patch available Fix from $1,6002016-08-08