IBM Planning Analytics Local 2.0 could allow a remote...
High severity
Unreviewed
Published
Dec 22, 2023
to the GitHub Advisory Database
•
Updated Dec 22, 2023
Description
Published by the National Vulnerability Database
Dec 22, 2023
Published to the GitHub Advisory Database
Dec 22, 2023
Last updated
Dec 22, 2023
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
References