CVE-2019-4056: Malicious File Upload
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-4056.
What is the severity of CVE-2019-4056?
The severity of CVE-2019-4056 is medium.
Which IBM products are affected by CVE-2019-4056?
IBM Control Desk, IBM Maximo Asset Management, IBM Maximo For Aviation, IBM Maximo For Life Sciences, IBM Maximo For Nuclear Power, IBM Maximo For Oil And Gas, IBM Maximo For Transportation, IBM Maximo For Utilities, IBM SmartCloud Control Desk, and IBM Tivoli Integration Composer are affected by CVE-2019-4056.
How does CVE-2019-4056 affect IBM Maximo Asset Management 7.6 Work Centers' application?
CVE-2019-4056 allows attackers to upload malicious files to IBM Maximo Asset Management 7.6 Work Centers' application.
Is there a fix available for CVE-2019-4056?
Yes, IBM has provided a fix for CVE-2019-4056. Please refer to the IBM support page for more information.