Lucene search

K
cveIbmCVE-2021-39017
HistoryJul 14, 2022 - 5:15 p.m.

CVE-2021-39017

2022-07-1417:15:08
ibm
web.nvd.nist.gov
43
2
ibm
engineering
lifecycle
optimization
publishing
vulnerability
remote
file upload
access controls
security

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

35.5%

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725.

Affected configurations

Nvd
Vulners
Node
ibmengineering_lifecycle_optimization_publishingMatch6.0.6
OR
ibmengineering_lifecycle_optimization_publishingMatch6.0.6.1
OR
ibmengineering_lifecycle_optimization_publishingMatch7.0
OR
ibmengineering_lifecycle_optimization_publishingMatch7.0.1
OR
ibmengineering_lifecycle_optimization_publishingMatch7.0.2
AND
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
ibmengineering_lifecycle_optimization_publishing6.0.6cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:6.0.6:*:*:*:*:*:*:*
ibmengineering_lifecycle_optimization_publishing6.0.6.1cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:6.0.6.1:*:*:*:*:*:*:*
ibmengineering_lifecycle_optimization_publishing7.0cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:7.0:*:*:*:*:*:*:*
ibmengineering_lifecycle_optimization_publishing7.0.1cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:7.0.1:*:*:*:*:*:*:*
ibmengineering_lifecycle_optimization_publishing7.0.2cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:7.0.2:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Engineering Lifecycle Optimization Publishing",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "6.0.6"
      },
      {
        "status": "affected",
        "version": "6.0.6.1"
      },
      {
        "status": "affected",
        "version": "7.0"
      },
      {
        "status": "affected",
        "version": "7.0.1"
      },
      {
        "status": "affected",
        "version": "7.0.2"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

35.5%

Related for CVE-2021-39017