CVE-2016-8932

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
ibmkenexa_lms
4.1
ibmkenexa_lms
4.2
ibmkenexa_lms
4.2.2
ibmkenexa_lms
4.2.3
ibmkenexa_lms
4.2.4
ibmkenexa_lms
5.0
ibmkenexa_lms
5.1
ibmkenexa_lms
5.2
𝑥
= Vulnerable software versions