CVE-2022-43864
26.01.2023, 21:17
IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 239427.
Vendor | Product | Version |
---|---|---|
ibm | business_automation_workflow | 21.0.1 ≤ 𝑥 ≤ 21.0.3.1 |
ibm | business_automation_workflow | 20.0.0.1 |
ibm | business_automation_workflow | 20.0.0.2 |
ibm | business_automation_workflow | 22.0.1 |
ibm | business_automation_workflow | 22.0.2 |
ibm | business_monitor | 8.5.5 |
ibm | business_monitor | 8.5.6 |
ibm | business_monitor | 8.5.7 |
𝑥
= Vulnerable software versions
References