IBM Cloud Pak for Automation Vulnerable to CSV Injection
CVE-2023-35899
Key Information
- Vendor
- IBM
- Status
- Cloud Pak For Automation
- Vendor
- CVE Published:
- 21 March 2024
Badges
Summary
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 259354.
Affected Version(s)
Cloud Pak for Automation = 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2
News Articles
Common Vulnerabilities and Exposures - Cloud WAF
Products Prophaze WAF 3.0 API Security Cloud WAF Kubernetes WAF On Premises WAF WAF API Gateway Bot Protection Layer 7 DDoS Protection Prophaze DNS Solution WAF-as-a-Service MSP and...
9 months ago
Refferences
CVSS V3.1
Timeline
Vulnerability published
First article discovered by prophaze.com
Vulnerability Reserved