CVE-2016-6104

IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
ibmsecurity_key_lifecycle_manager
2.5.0
ibmsecurity_key_lifecycle_manager
2.5.0.0
ibmsecurity_key_lifecycle_manager
2.5.0.1
ibmsecurity_key_lifecycle_manager
2.5.0.2
ibmsecurity_key_lifecycle_manager
2.5.0.3
ibmsecurity_key_lifecycle_manager
2.5.0.4
ibmsecurity_key_lifecycle_manager
2.5.0.5
ibmsecurity_key_lifecycle_manager
2.5.0.6
ibmsecurity_key_lifecycle_manager
2.5.0.7
ibmsecurity_key_lifecycle_manager
2.6.0
ibmsecurity_key_lifecycle_manager
2.6.0.1
ibmsecurity_key_lifecycle_manager
2.6.0.2
𝑥
= Vulnerable software versions