CVE-2018-2006
21.02.2019, 17:29
IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008.
Vendor | Product | Version |
---|---|---|
ibm | robotic_process_automation_with_automation_anywhere | 11.0.0.0 ≤ 𝑥 < 11.0.0.4 |
𝑥
= Vulnerable software versions
References