PT-2023-13235 · Ibm · Ibm Security Directory Suite Va

Published

2023-06-15

·

Updated

2023-06-21

·

CVE-2022-33166

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19
Description The issue allows a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
Recommendations For IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19, consider restricting file upload capabilities to prevent the processing of malicious files until a fix is available. As a temporary workaround, limit the types of files that can be uploaded to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-33166

Affected Products

Ibm Security Directory Suite Va