CVE Published: 07/02/2017 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: ibm |
Vendor: IBM Corporation |
Product: Key Lifecycle Manager Status : PUBLISHED
CVE-2016-6104 Description
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.