CVE-2017-1161
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.
IBM API Connect 5.0.6.0 podría permitir a un atacante remoto ejecutar comandos arbitrarios en el sistema, causados por una validación incorrecta de las URL del Developer Portal. Al crear URLs malintencionadas, un atacante podría explotar esta vulnerabilidad para ejecutar comandos arbitrarios en el sistema con los privilegios del usuario de datos www-data user. IBM X-Force ID: 122956.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-30 CVE Reserved
- 2017-04-17 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97665 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/docview.wss?uid=swg22000316 | 2017-04-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Api Connect Search vendor "Ibm" for product "Api Connect" | 5.0.6.0 Search vendor "Ibm" for product "Api Connect" and version "5.0.6.0" | - |
Affected
|