Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 184979.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Data Risk Manager 代码问题漏洞
Vulnerability Description
IBM Data Risk Manager是美国IBM公司的一款数据风险管理器。该产品支持发现、分析和可视化业务风险数据等。 IBM Data Risk Manager(iDNA)2.0.6存在代码问题漏洞,该漏洞源于数据扩展名验证不正确,该漏洞允许攻击者通过身份验证的用户上载任意文件,通过发送特制的HTTP请求,远程攻击者可以利用此漏洞来上传恶意文件,这可以使攻击者在易受攻击的系统上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A