CVE-2016-8932

EUVD-2016-9757
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
ibmkenexa_lms
4.1
ibmkenexa_lms
4.2
ibmkenexa_lms
4.2.2
ibmkenexa_lms
4.2.3
ibmkenexa_lms
4.2.4
ibmkenexa_lms
5.0
ibmkenexa_lms
5.1
ibmkenexa_lms
5.2
𝑥
= Vulnerable software versions