IBM Security Verify Directory
cpe:2.3:a:ibm:security_verify_directory:*:*:*:*:*:*:*
- >= 10.0.0, <= 10.0.0.3
A vulnerability allowing unrestricted file uploads has been identified in IBM Security Verify Directory (Container) versions 10.0.0 through 10.0.0.3. This issue arises because the application does not properly validate file types, enabling privileged users to upload malicious files. These files could be sent to other users to facilitate further attacks against the system.
Exploitation of this vulnerability could lead to unauthorized file uploads, allowing for the distribution of malicious files that could be used to compromise the system or its users.
Users are advised to update to IBM Security Verify Directory (Container) version 10.0.0.4 or later. The update can be downloaded from the IBM Security Verify Directory version 10.0.0.4 download document.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.