CVE-2023-35018: IBM Security Verify Governance file upload
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
Other sources
IBM Security Verify Governance, Identity Manager could allow a local user to escalate their privileges due to improper access controls.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35018?
The severity of CVE-2023-35018 is high with a severity value of 7.8.
How can a local user escalate their privilege with CVE-2023-35018?
A local user can escalate their privilege by uploading arbitrary files due to improper file validation in IBM Security Verify Governance 10.0.
What is the affected software of CVE-2023-35018?
The affected software of CVE-2023-35018 is IBM Security Verify Governance - Identity Manager virtual appliance component version prior to 10.0.2 Fixpack 0.
Are there any references for CVE-2023-35018?
Yes, there are references available for CVE-2023-35018. You can find them at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/259382), [Link 2](https://www.ibm.com/support/pages/node/7050358), [Link 3](https://exchange.xforce.ibmcloud.com/vulnerabilities/257779).
What is the CWE number for CVE-2023-35018?
The CWE number for CVE-2023-35018 is 434.