IBM Watson Knowledge Catalog CSV injection
CVE-2023-28958
7HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 10 July 2023
What is CVE-2023-28958?
The IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is susceptible to CSV Injection. This vulnerability arises from insufficient validation of CSV file contents, enabling a remote attacker to craft malicious CSV files that could execute arbitrary commands on the system. Proper mitigation strategies should be implemented to safeguard sensitive information and protect against unauthorized command execution.
Affected Version(s)
Watson Knowledge Catalog on Cloud Pak for Data 4.0