Arbitrary Code Execution via Unrestricted File Upload in IBM Rational Publishing Engine

Arbitrary Code Execution via Unrestricted File Upload in IBM Rational Publishing Engine

CVE-2016-2914 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:P

Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.

Learn more about our Cis Benchmark Audit For Ibm I.