CVE-2020-4928
Description
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.
- CVSS Version 3.1
- CVSS Version 3.0
- CVSS Version 2.0
nvd
CVE ID: CVE-2020-4928
Base Score: 6.7
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 0.8
us.ibm
CVE ID: CVE-2020-4928
Base Score: 6.7
Base Severity: MEDIUM
Vector String:CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd
CVE ID: CVE-2020-4928
Base Score: 4.6
Base Severity: MEDIUM
Vector String:AV:L/AC:L/Au:N/C:P/I:P/A:P