ZeroHour

CVE-2016-6104

CVSS 3.0
7.2 high
EPSS
3%p85
Published
()
Modified
Description

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.

Vendors
ibm
Products
security key lifecycle manager
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.