Input validation error in ASP.NET Core MVC - CVE-2018-8416
Published: November 14, 2018
Vulnerability identifier: #VU15881
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8416
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files to the system.
The vulnerability exists due to insufficient validation of user-supplied input when processing file uploads within .NET Core. A remote attacker can upload arbitrary file to a limited number of location on the system.
Affected software
ASP.NET Core MVC
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2018-8416
Install updates from vendor's website.
IBM Robotic Process Automation - addressed in versions 21.0.7.16, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.16, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.16, 23.0.16