Lucene search

K
zdiAbdulAziz HaririHP Zero Day InitiativeZDI-14-017
HistoryFeb 13, 2014 - 12:00 a.m.

IBM Platform Symphony DE Remote Code Execution Vulnerability

2014-02-1300:00:00
AbdulAziz HaririHP Zero Day Initiative
www.zerodayinitiative.com
15

0.877 High

EPSS

Percentile

98.7%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Platform Symphony DE. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists in the way SOAP requests are handled. A malformed SOAP request would overwrite a statically sized buffer that could allow remote code execution in the context of the process.

0.877 High

EPSS

Percentile

98.7%