CVE-2021-35485: Malicious File Upload
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35485?
CVE-2021-35485 has been classified as a high-severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2021-35485?
To fix CVE-2021-35485, update Nokia IMPACT to a version beyond 19.11.2.10-20210118042150283 that addresses this vulnerability.
Who is affected by CVE-2021-35485?
CVE-2021-35485 affects authenticated users of Nokia IMPACT versions up to 19.11.2.10-20210118042150283.
What can an attacker do with CVE-2021-35485?
An attacker can exploit CVE-2021-35485 to upload malicious server-side executable files, potentially allowing remote code execution.
When was CVE-2021-35485 disclosed?
CVE-2021-35485 was disclosed in 2021, highlighting a security weakness in Nokia IMPACT.