CVE Published: 22/09/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: ibm |
Vendor: IBM |
Product: Data Risk Manager Status : PUBLISHED
CVE-2020-4620 Description
IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 184979.