← back
CVE-2023-49886

IBM Transformation Extender Advanced code execution

CVSS 9.8 CRITICALEPSS 0.6%CWE-502
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
06 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H