Arbitrary file upload in formidable - CVE-2022-29622
Published: July 13, 2022 / Updated: July 22, 2022
Vulnerability identifier: #VU65264
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2022-29622
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Affected software:
formidable
Cognos Dashboards on Cloud Pak for Data
App Connect Enterprise Certified Container
Netcool Operations Insight
IBM Cognos Analytics
formidable
Cognos Dashboards on Cloud Pak for Data
App Connect Enterprise Certified Container
Netcool Operations Insight
IBM Cognos Analytics
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of file extension when uploading files. A remote attacker can upload and execute arbitrary file on the system.
How to mitigate CVE-2022-29622
Install update from vendor's website.