CVE-2023-35903: Low severity ibm security verify governance, identity manager virtual appliance component vulnerability
Published Oct 11, 2023
·Updated
IBM Security Verify Governance could allow a privileged use to upload arbitrary files due to improper file validation.
Affected Software
1 affected component
IBM Security Verify Governance - Identity Manager virtual appliance component<=All prior to 10.0.2 Fixpack 0
Event History
Oct 11, 2023
CVE Published
via IBM·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-35903.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Security Verify Governance could allow a privileged user to upload arbitrary files due to improper file validation.'
3
What is the severity of CVE-2023-35903?
The severity of CVE-2023-35903 is low with a severity value of 3.3.
4
Which IBM product is affected by this vulnerability?
IBM Security Verify Governance - Identity Manager virtual appliance component is affected by this vulnerability.
5
How can the vulnerability be exploited?
A privileged user can exploit this vulnerability by uploading arbitrary files due to improper file validation.