漏洞标题
IBM DevOps Deploy / IBM UrbanCode Deploy命令注入漏洞
漏洞描述信息
IBM DevOps Deploy 8.0 至 8.0.1.4,8.1 至 8.1.0.0 / IBM UrbanCode Deploy 7.0 至 7.0.5.25,7.1 至 7.1.2.21,7.2 至 7.2.3.14 以及 7.3 至 7.3.2.9 存在漏洞,可能允许远程特权认证攻击者通过发送包含特殊元素的特制输入在系统上执行任意命令。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
输入验证不恰当
漏洞标题
IBM DevOps Deploy / IBM UrbanCode Deploy command injection
漏洞描述信息
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)