Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rational_appscan | Ibm | 5.2 (including) | 5.2 (including) |
Rational_appscan | Ibm | 5.4 (including) | 5.4 (including) |
Rational_appscan | Ibm | 5.5.0 (including) | 5.5.0 (including) |
Rational_appscan | Ibm | 5.5.0.1 (including) | 5.5.0.1 (including) |
Rational_appscan | Ibm | 5.5.0.2 (including) | 5.5.0.2 (including) |
Rational_appscan | Ibm | 5.6.0 (including) | 5.6.0 (including) |
Rational_appscan | Ibm | 5.6.0.3 (including) | 5.6.0.3 (including) |
Rational_appscan | Ibm | 8.0.0 (including) | 8.0.0 (including) |
Rational_appscan | Ibm | 8.0.0.1 (including) | 8.0.0.1 (including) |
Rational_appscan | Ibm | 8.0.0.2 (including) | 8.0.0.2 (including) |
Rational_appscan | Ibm | 8.0.0.3 (including) | 8.0.0.3 (including) |
Rational_appscan | Ibm | 8.0.1 (including) | 8.0.1 (including) |
Rational_appscan | Ibm | 8.0.1.1 (including) | 8.0.1.1 (including) |
Rational_appscan | Ibm | 8.5.0 (including) | 8.5.0 (including) |
Rational_appscan | Ibm | 8.5.0.0 (including) | 8.5.0.0 (including) |