[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255716

 
 

909

 
 

198991

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-9693Date: (C)2017-03-09   (M)2023-12-22


IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.1CVSS Score : 6.8
Exploit Score: 1.8Exploit Score: 8.6
Impact Score: 3.7Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: PARTIAL
Integrity: LOW 
Availability: LOW 
  
Reference:
BID-98074
https://www.ibm.com/support/docview.wss?uid=swg21998655

CPE    63
cpe:/a:ibm:business_process_manager:8.5.0.2::~~advanced~~~
cpe:/a:ibm:business_process_manager:7.5.0.0::~~standard~~~
cpe:/a:ibm:business_process_manager:8.5.7.0::~~standard~~~
cpe:/a:ibm:business_process_manager:8.0.1.0::~~standard~~~
...
CWE    1
CWE-20

© SecPod Technologies