Input validation error in Werkzeug - CVE-2019-14322
Published: July 29, 2019 / Updated: September 20, 2024
Vulnerability identifier: #VU19553
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14322
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to access arbitrary files on the target system.
The vulnerability exists due to the "SharedDataMiddleware" mishandles drive names (such as C:) in Windows pathnames. A remote attacker can access arbitrary files on the target system.
Affected software
Werkzeug
IBM Cloud Pak for Data System
QRadar Assistant
IBM Cloud Pak for Data System
QRadar Assistant
How to mitigate CVE-2019-14322
Install updates from vendor's website.
Werkzeug - update to 0.15.5
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
QRadar Assistant - update to 3.7.0
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
QRadar Assistant - update to 3.7.0