First published: Wed Feb 01 2017(Updated: )
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Kenexa LMS | =4.1 | |
IBM Kenexa LMS | =4.2 | |
IBM Kenexa LMS | =4.2.2 | |
IBM Kenexa LMS | =4.2.3 | |
IBM Kenexa LMS | =4.2.4 | |
IBM Kenexa LMS | =5.0 | |
IBM Kenexa LMS | =5.1 | |
IBM Kenexa LMS | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8932 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2016-8932, it is recommended to apply the latest security patches and updates provided by IBM for the affected versions of Kenexa LMS.
CVE-2016-8932 affects IBM Kenexa LMS versions 4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2.
The implications of CVE-2016-8932 include the potential for attackers to upload malicious files and execute arbitrary code on the server.
As of now, there have been no widespread reports of active exploitation of CVE-2016-8932, but it remains a significant risk if not addressed.