9.8
CVE-2023-35899
- EPSS 0.09%
- Veröffentlicht 21.03.2024 02:47:58
- Zuletzt bearbeitet 05.03.2025 18:24:35
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Cloud Pak for Automation CSV injection
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 259354.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak For Business Automation Version18.0.0
Ibm ≫ Cloud Pak For Business Automation Version18.0.1
Ibm ≫ Cloud Pak For Business Automation Version18.0.2
Ibm ≫ Cloud Pak For Business Automation Version19.0.1
Ibm ≫ Cloud Pak For Business Automation Version19.0.2
Ibm ≫ Cloud Pak For Business Automation Version19.0.3
Ibm ≫ Cloud Pak For Business Automation Version20.0.1
Ibm ≫ Cloud Pak For Business Automation Version20.0.2
Ibm ≫ Cloud Pak For Business Automation Version20.0.3
Ibm ≫ Cloud Pak For Business Automation Version21.0.1
Ibm ≫ Cloud Pak For Business Automation Version21.0.2
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Update-
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_001
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_002
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_003
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_004
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_005
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_006
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_007
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_008
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_009
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_010
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_011
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_012
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_013
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_014
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_015
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_016
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_017
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_018
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_019
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_020
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_021
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_022
Ibm ≫ Cloud Pak For Business Automation Version21.0.3 Updateinterim_fix_023
Ibm ≫ Cloud Pak For Business Automation Version22.0.1
Ibm ≫ Cloud Pak For Business Automation Version22.0.2
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Update-
Ibm ≫ Cloud Pak For Business Automation Version23.0.1 Updateinterim_fix_001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.259 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-1236 Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.