CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:planning_analytics:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7096528 - Vendor Advisory () https://www.ibm.com/support/pages/node/7096528 - Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.0

29 Dec 2023, 18:52

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/265567 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7096528 - () https://www.ibm.com/support/pages/node/7096528 - Vendor Advisory
CPE cpe:2.3:a:ibm:planning_analytics:2.0:*:*:*:*:*:*:*
First Time Ibm planning Analytics
Ibm
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 9.8
Summary
  • (es) IBM Planning Analytics Local 2.0 podría permitir a un atacante remoto cargar archivos arbitrarios, provocados por la validación inadecuada de las extensiones de archivo. Al enviar una solicitud HTTP especialmente manipulada, un atacante remoto podría aprovechar esta vulnerabilidad para cargar un script malicioso, lo que podría permitir al atacante ejecutar código arbitrario en el sistema vulnerable. ID de IBM X-Force: 265567.

22 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-22 16:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42017

Mitre link : CVE-2023-42017

CVE.ORG link : CVE-2023-42017


JSON object : View

Products Affected

ibm

  • planning_analytics
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type