IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21997988 | patch vendor advisory |
http://www.securityfocus.com/bid/95980 | vdb entry third party advisory |