CVE-2014-0607
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://support.attachmate.com/techdocs/2700.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| attachmate | verastream_process_designer | {"endIncluding":"6.0"} | |
| attachmate | verastream_process_designer | 6.0 | |
References
Verify integrity in audit chain (admin only). AS-IS.