Local File Upload Vulnerability in IBM Cloud Pak System
CVE-2020-4928
6.7MEDIUM
What is CVE-2020-4928?
The local file upload vulnerability in IBM Cloud Pak System 2.3 permits an attacker with local access to upload arbitrary files. By manipulating the request and altering the file extension, the attacker can execute arbitrary code on the server, potentially leading to severe security breaches. This vulnerability could exploit various attack vectors if not mitigated, emphasizing the need for robust security measures.
Affected Version(s)
Cloud Pak System 2.3