CVE-2021-39017: Medium severity ibm pub vulnerability
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725.
Other sources
IBM Engineering Lifecycle Optimization - Publishing could allow a remote attacker to upload arbitrary files, caused by improper access controls.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-39017?
CVE-2021-39017 is a vulnerability in IBM Engineering Lifecycle Optimization - Publishing that could allow a remote attacker to upload arbitrary files due to improper access controls.
What is the severity of CVE-2021-39017?
The severity of CVE-2021-39017 is medium with a CVSS score of 6.5.
Which versions of IBM Engineering Lifecycle Optimization - Publishing are affected by CVE-2021-39017?
Versions 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 of IBM Engineering Lifecycle Optimization - Publishing are affected by CVE-2021-39017.
How can a remote attacker exploit CVE-2021-39017?
A remote attacker can exploit CVE-2021-39017 by uploading arbitrary files due to improper access controls.
How can I fix the CVE-2021-39017 vulnerability?
To fix the CVE-2021-39017 vulnerability, it is recommended to update to a patched version of IBM Engineering Lifecycle Optimization - Publishing.