CVE-2015-0126

IBM Leads 7.x-9.1.1.0.2 - Authenticated File Upload Restriction Bypass via Modified Extension

Title source: llm
STIX 2.1

Description

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to bypass intended file-upload restrictions via a modified extension.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21902807

Scores

EPSS 0.0113
EPSS Percentile 63.0%

Details

Status published
Products (10)
ibm/leads 7.1.0
ibm/leads 7.1.1
ibm/leads 7.5.0
ibm/leads 8.1.0
ibm/leads 8.2.0
ibm/leads 8.5.0
ibm/leads 8.6.0
ibm/leads 9.0.0
ibm/leads 9.1.0
ibm/leads 9.1.1
Published Jun 28, 2015
Tracked Since Feb 18, 2026