CVE-2022-33166: IBM Security Directory Suite VA file upload
IBM Security Directory Server could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
Other sources
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-33166.
What is the severity of CVE-2022-33166?
The severity of CVE-2022-33166 is high (7.2).
Which IBM product is affected by CVE-2022-33166?
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 is affected by CVE-2022-33166.
How can a privileged user exploit CVE-2022-33166?
A privileged user can exploit CVE-2022-33166 by uploading malicious files of dangerous types that can be automatically processed within the product's environment.
Is there any additional information available about CVE-2022-33166?
Yes, you can find additional information about CVE-2022-33166 at the following references: [IBM X-Force ID: 228586](https://exchange.xforce.ibmcloud.com/vulnerabilities/228586) and [IBM Support Page](https://www.ibm.com/support/pages/node/7001693).