CVE-2023-35899

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Mar 21, 2024
CWE ID 1236

Summary

CVE-2023-35899 is a newly disclosed vulnerability affecting various versions of IBM Cloud Pak for Automation (18.0.0 to 22.0.2). This issue permits a remote attacker to inject malicious CSV (Comma Separated Values) files, exploiting the system's improper validation of csv file contents. Successful exploitation could lead to the execution of arbitrary commands on the affected system, as reported by IBM X-Force with ID 259354. IBM users are strongly advised to update their installations to the latest, secure version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share