cbcvebase.
CVE-2016-8932
published 2017-02-01

CVE-2016-8932: IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

Affected

19 ranges
VendorProductVersion rangeFixed in
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibmkenexa_lms
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
ibm_corporationkenexa_lms_on_cloud
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.33.1.2-7ubuntu2.3
libarchivelibarchive>= 0 < 3.1.2-11ubuntu0.16.04.23.1.2-11ubuntu0.16.04.2

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM