Vulnerability in ILIAS Workflow Engine Allows Unauthorized Command Execution
CVE-2023-36485

7.2HIGH

Key Information:

Vendor

Ilias

Status
Vendor
CVE Published:
25 December 2023

What is CVE-2023-36485?

The ILIAS workflow engine, present in versions before 7.23 and 8 before 8.3, is susceptible to a flaw that permits authenticated users to execute arbitrary system commands on the application server. This occurs via a crafted BPMN2 workflow definition file, presenting serious security concerns for users of the platform. Proper remediation is crucial to protect against this exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.