Arbitrary File Upload Vulnerability Affects IBM Engineering Lifecycle Optimization Publishing
CVE-2023-45188
9.8CRITICAL
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 9 June 2024
What is CVE-2023-45188?
IBM Engineering Lifecycle Optimization Publishing versions 7.0.2 and 7.0.3 are susceptible to a remote file upload vulnerability, stemming from inadequate validation of file extensions. This weakness enables an attacker to send a specially crafted request, which could facilitate the upload of malicious files. Successful exploitation may lead to unauthorized code execution, compromising the integrity and security of the affected system.
Affected Version(s)
Engineering Lifecycle Optimization Publishing 7.0.2, 7.0.3