CVE-2023-35899: IBM Cloud Pak for Automation CSV injection
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 259354.
Other sources
IBM ICP4A - Business Automation Insights Core is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35899?
The severity of CVE-2023-35899 is classified as high due to the potential for remote code execution.
How do I fix CVE-2023-35899?
To fix CVE-2023-35899, ensure you upgrade to the latest version of IBM Cloud Pak for Business Automation that addresses this vulnerability.
Who is affected by CVE-2023-35899?
CVE-2023-35899 affects users of IBM Cloud Pak for Automation versions 18.0.0 to 22.0.2.
What kind of attack is possible with CVE-2023-35899?
CVE-2023-35899 allows a remote attacker to execute arbitrary commands on the system due to CSV injection.
When was CVE-2023-35899 disclosed?
CVE-2023-35899 was disclosed in 2023 as a vulnerability in the IBM Cloud Pak for Automation products.