CVE-2019-4013: Malicious File Upload
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4013?
CVE-2019-4013 has a critical severity rating due to the potential for remote code execution with root privileges.
How do I fix CVE-2019-4013?
To mitigate CVE-2019-4013, update IBM BigFix Platform to a version later than 9.5.11.
Who is affected by CVE-2019-4013?
CVE-2019-4013 affects authenticated users of IBM BigFix Platform versions between 9.5.0 and 9.5.11.
What impact does CVE-2019-4013 have?
CVE-2019-4013 allows unauthenticated users to execute arbitrary code on the server, leading to a complete system compromise.
Is there a known exploit for CVE-2019-4013?
Yes, CVE-2019-4013 is known to be exploitable by authenticated users, enabling file uploads that lead to code execution.