CVE-2016-6124

EUVD-2016-7058
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
ibmkenexa_lms_on_cloud
13.1
ibmkenexa_lms_on_cloud
13.2
ibmkenexa_lms_on_cloud
13.2.2
ibmkenexa_lms_on_cloud
13.2.3
ibmkenexa_lms_on_cloud
13.2.4
𝑥
= Vulnerable software versions