PT-2024-12521 · Ibm · Ibm Cloud Pak For Automation

Published

2024-03-05

·

Updated

2024-03-22

·

CVE-2023-35899

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Automation versions 18.0.0 through 22.0.2
Description The issue is caused by improper validation of csv file contents, allowing a remote attacker to execute arbitrary commands on the system. This can lead to unauthorized access and control of the system.
Recommendations For IBM Cloud Pak for Automation versions 18.0.0 through 22.0.2, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to csv file uploads and validating all csv file contents to minimize the risk of exploitation.

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-35899

Affected Products

Ibm Cloud Pak For Automation