IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7234122 |
![]() ![]() |
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Thu, 10 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks. | |
Title | IBM Analytics Content Hub file upload | |
First Time appeared |
Ibm
Ibm analytics Content Hub |
|
Weaknesses | CWE-434 | |
CPEs | cpe:2.3:a:ibm:analytics_content_hub:2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:analytics_content_hub:2.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:analytics_content_hub:2.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:analytics_content_hub:2.3:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm analytics Content Hub |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-07-10T14:15:19.208Z
Updated: 2025-07-10T20:16:05.235Z
Reserved: 2024-06-28T09:34:46.058Z
Link: CVE-2024-39752

Updated: 2025-07-10T20:16:00.700Z

Status : Awaiting Analysis
Published: 2025-07-10T15:15:26.000
Modified: 2025-07-15T13:24:41.097
Link: CVE-2024-39752

No data.