First published: Wed Oct 11 2023(Updated: )
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance - Identity Manager virtual appliance component | <=All prior to 10.0.2 Fixpack 0 | |
IBM Security Verify Governance | >=10.0<10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35018 is high with a severity value of 7.8.
A local user can escalate their privilege by uploading arbitrary files due to improper file validation in IBM Security Verify Governance 10.0.
The affected software of CVE-2023-35018 is IBM Security Verify Governance - Identity Manager virtual appliance component version prior to 10.0.2 Fixpack 0.
Yes, there are references available for CVE-2023-35018. You can find them at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/259382), [Link 2](https://www.ibm.com/support/pages/node/7050358), [Link 3](https://exchange.xforce.ibmcloud.com/vulnerabilities/257779).
The CWE number for CVE-2023-35018 is 434.