PT-2023-13235 · Ibm · Ibm Security Directory Suite Va
CVE-2022-33166
·
Publicado
2023-06-15
·
Atualizado
2023-06-21
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19
Description
The issue allows a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
Recommendations
For IBM Security Directory Suite VA versions 8.0.1 through 8.0.1.19, consider restricting file upload capabilities to prevent the processing of malicious files until a fix is available. As a temporary workaround, limit the types of files that can be uploaded to minimize the risk of exploitation.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Security Directory Suite Va