PT-2023-13235 · Ibm · Ibm Security Directory Suite Va

CVE-2022-33166

·

Publicado

2023-06-15

·

Atualizado

2023-06-21

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19
Description The issue allows a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
Recommendations For IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19, consider restricting file upload capabilities to prevent the processing of malicious files until a fix is available. As a temporary workaround, limit the types of files that can be uploaded to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-33166

Produtos afetados

Ibm Security Directory Suite Va