CVE-2021-38965
https://notcve.org/view.php?id=CVE-2021-38965
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346. IBM FileNet Content Manager versiones 5.5.4, 5.5.6 y 5.5.7, podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema mediante el envío de una petición especialmente diseñada. IBM X-Force ID: 212346 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212346 https://www.ibm.com/support/pages/node/6509840 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2020-4759
https://notcve.org/view.php?id=CVE-2020-4759
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736. IBM FileNet Content Manager versiones 5.5.4 y 5.5.5, es potencialmente vulnerable a una Inyección CVS. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, causado por una comprobación inapropiada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/188736 https://www.ibm.com/support/pages/node/6336917 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •