IBM Business Automation Workflow information disclosure
CVE-2022-43864
7.5HIGH
What is CVE-2022-43864?
IBM Business Automation Workflow version 22.0.2 is susceptible to a directory traversal vulnerability that enables an attacker to manipulate URL requests using 'dot dot' sequences (/../). This flaw allows unauthorized viewing of arbitrary files on the system, potentially exposing sensitive information. Proper input validation and safeguarding techniques are essential to mitigate the risk posed by this vulnerability, allowing for a more secure application environment.
Affected Version(s)
Business Monitor 8.5.5, 8.5.6, 8.5.7