Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2017
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-09-12
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.
CVSS Score
4.7
EPSS Score
0.001
Published
2017-09-12
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
CVSS Score
6.7
EPSS Score
0.001
Published
2017-09-12
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
CVSS Score
6.7
EPSS Score
0.001
Published
2017-09-12
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
CVSS Score
9.8
EPSS Score
0.017
Published
2017-09-12
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
CVSS Score
9.8
EPSS Score
0.005
Published
2017-09-12
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
CVSS Score
8.8
EPSS Score
0.004
Published
2017-09-12
In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in the function GetVirtualPixels in MagickCore/cache.c) via a crafted file.
CVSS Score
6.5
EPSS Score
0.005
Published
2017-09-12
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
CVSS Score
7.8
EPSS Score
0.001
Published
2017-09-12
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
CVSS Score
7.8
EPSS Score
0.001
Published
2017-09-12


Contact Us

Shodan ® - All rights reserved