External Control of File Name or Path
CVE-2023-26282
Summary
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or data on the system. IBM X-Force ID: 248415.
- HIGH
- PHYSICAL
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-73 - External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
References
Advisory Timeline
- Published