CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:planning_analytics:2.0:*:*:*:*:*:*:*

History

29 Dec 2023, 18:52

Type Values Removed Values Added
First Time Ibm
Ibm planning Analytics
Summary
  • (es) IBM Planning Analytics Local 2.0 podría permitir a un atacante remoto cargar archivos arbitrarios, provocados por la validación inadecuada de las extensiones de archivo. Al enviar una solicitud HTTP especialmente manipulada, un atacante remoto podría aprovechar esta vulnerabilidad para cargar un script malicioso, lo que podría permitir al atacante ejecutar código arbitrario en el sistema vulnerable. ID de IBM X-Force: 265567.
CPE cpe:2.3:a:ibm:planning_analytics:2.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 9.8
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7096528 - () https://www.ibm.com/support/pages/node/7096528 - Vendor Advisory

22 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-22 16:15

Updated : 2023-12-29 18:52


NVD link : CVE-2023-42017

Mitre link : CVE-2023-42017

CVE.ORG link : CVE-2023-42017


JSON object : View

Products Affected

ibm

  • planning_analytics
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type