CVE-2026-6935
Beschrijving NL
IBM Concert 1.0.0 tot en met 3.0.0 roept besturingssysteemcommando's aan zonder volledig in aanmerking komende uitvoerbare paden of het adequaat beperken van de zoekpadresolutie. Als gevolg hiervan kan een aanvaller met lokale systeemtoegang de zoekpadomgeving manipuleren om niet-vertrouwde of kwaadaardige code uit te voeren.
Origineel (Engels) tonen
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.