Unrestricted upload of file with dangerous type in IBM Security Identity Manager Virtual Appliance - CVE-2018-1453

 

Unrestricted upload of file with dangerous type in IBM Security Identity Manager Virtual Appliance - CVE-2018-1453

Published: July 27, 2018 / Updated: July 27, 2018


Vulnerability identifier: #VU14025
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1453
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions and upload files to the target system.

The vulnerability exists in IBM Security Identity Manager Virtual Appliance due to unspecified flaw. A remote attacker can upload files with potentially dangerous file types to the target system that may be automatically processed on the target system.


Affected software

IBM Security Identity Manager Virtual Appliance

How to mitigate CVE-2018-1453

Update to version 7.0.1.7.

IBM Security Identity Manager Virtual Appliance - update to 7.0.1.7

External References

Related Security Bulletins