CVE-2023-36485: High severity ILIAS ILIAS vulnerability
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36485?
CVE-2023-36485 is considered a high severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary system commands.
How do I fix CVE-2023-36485?
To fix CVE-2023-36485, update ILIAS to version 7.23 or later, or version 8.3 or later.
What types of users are affected by CVE-2023-36485?
CVE-2023-36485 affects remote authenticated users who can exploit the vulnerability through a crafted BPMN2 workflow definition file.
What impact does CVE-2023-36485 have on systems?
CVE-2023-36485 can lead to unauthorized system command execution, potentially compromising the application server and its data.
In which versions of ILIAS is CVE-2023-36485 present?
CVE-2023-36485 is present in ILIAS versions prior to 7.23 and between 8.0 and 8.2.