Security Advisory

CVE-2017-1161

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-17 21:00:00
Last updated 2024-08-05 13:25:17
Assigner ibm
CVSS score not scored
State PUBLISHED

Description

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.