Specially Crafted YAML File Can Bypass Security Measures in IBM ManageIQ
CVE-2024-43191
7.2HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 26 September 2024
What is CVE-2024-43191?
IBM ManageIQ is susceptible to a remote command execution vulnerability that arises when an attacker with authenticated access crafts a malicious YAML file request. This manipulation could potentially allow unauthorized execution of arbitrary commands on the system, leading to further exploitation. Users of IBM ManageIQ are advised to review their configurations and ensure proper security measures are implemented to mitigate potential threats.
Affected Version(s)
Cloud Pak for Multicloud Management 2.3, 2.3 FP8