CVE-2023-35897
06.10.2023, 14:15
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.
Vendor | Product | Version |
---|---|---|
ibm | storage_protect | 8.1.0.0 ≤ 𝑥 ≤ 8.1.19.0 |
ibm | storage_protect | 8.1.0.0 ≤ 𝑥 ≤ 8.1.19.0 |
ibm | storage_protect_client | 8.1.0.0 ≤ 𝑥 ≤ 8.1.19.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-94 - Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
- CWE-427 - Uncontrolled Search Path ElementThe product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.