cbcvebase.
CVE-2020-4928
published 2021-01-04

CVE-2020-4928: IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the…

medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmcloud_pak_system
ibmcloud_pak_system>= 2.3.0.0 < 2.3.3.32.3.3.3