CVE-2013-6332
Published Feb 6, 2014
Last updated 7 years ago
Overview
- Description
- Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 8.5
- Impact score
- 10
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Evaluator
- Comment
- Per: http://cwe.mitre.org/data/definitions/434.html "CWE-434: Unrestricted Upload of File with Dangerous Type"
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:algo_one:4.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8120AA8D-23E8-4514-8BF6-9F3684C53E02" }, { "criteria": "cpe:2.3:a:ibm:algo_one:4.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3ABBD10-48EF-4417-AD6F-BE518149CE3A" }, { "criteria": "cpe:2.3:a:ibm:algo_one:4.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FAC17D9-E48E-49A6-B5AE-1BA0EAD58228" }, { "criteria": "cpe:2.3:a:ibm:algo_one:4.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "164E8913-DFA0-4566-8DDB-94465F708541" }, { "criteria": "cpe:2.3:a:ibm:algo_one:4.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A672407B-4966-4A89-BF1B-2644CEAF172B" }, { "criteria": "cpe:2.3:a:ibm:algo_one:5.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67A8F72A-746C-49E9-9FF3-06C31C0B22FB" } ], "operator": "OR" } ] } ]