7.2
CVE-2016-6104
- EPSS 2.69%
- Veröffentlicht 07.02.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.0
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.1
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.2
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.3
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.4
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.5
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.6
Ibm ≫ Security Key Lifecycle Manager Version 2.5.0.7
Ibm ≫ Security Key Lifecycle Manager Version 2.6.0
Ibm ≫ Security Key Lifecycle Manager Version 2.6.0.1
Ibm ≫ Security Key Lifecycle Manager Version 2.6.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.69% | 0.839 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
http://www.ibm.com/support/docview.wss?uid=swg21997988
http://www.securityfocus.com/bid/95980