Lucene search

K
cveIbmCVE-2015-0126
HistoryJun 28, 2015 - 10:59 p.m.

CVE-2015-0126

2015-06-2822:59:04
ibm
web.nvd.nist.gov
18
ibm
leads
remote
authentication
file-upload
restrictions
bypass
cve-2015-0126

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.5%

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.

Affected configurations

Nvd
Node
ibmleadsMatch7.1.0
OR
ibmleadsMatch7.1.1
OR
ibmleadsMatch7.5.0
OR
ibmleadsMatch8.1.0
OR
ibmleadsMatch8.2.0
OR
ibmleadsMatch8.5.0
OR
ibmleadsMatch8.6.0
OR
ibmleadsMatch9.0.0
OR
ibmleadsMatch9.1.0
OR
ibmleadsMatch9.1.1
VendorProductVersionCPE
ibmleads7.1.0cpe:2.3:a:ibm:leads:7.1.0:*:*:*:*:*:*:*
ibmleads7.1.1cpe:2.3:a:ibm:leads:7.1.1:*:*:*:*:*:*:*
ibmleads7.5.0cpe:2.3:a:ibm:leads:7.5.0:*:*:*:*:*:*:*
ibmleads8.1.0cpe:2.3:a:ibm:leads:8.1.0:*:*:*:*:*:*:*
ibmleads8.2.0cpe:2.3:a:ibm:leads:8.2.0:*:*:*:*:*:*:*
ibmleads8.5.0cpe:2.3:a:ibm:leads:8.5.0:*:*:*:*:*:*:*
ibmleads8.6.0cpe:2.3:a:ibm:leads:8.6.0:*:*:*:*:*:*:*
ibmleads9.0.0cpe:2.3:a:ibm:leads:9.0.0:*:*:*:*:*:*:*
ibmleads9.1.0cpe:2.3:a:ibm:leads:9.1.0:*:*:*:*:*:*:*
ibmleads9.1.1cpe:2.3:a:ibm:leads:9.1.1:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.5%

Related for CVE-2015-0126