Path traversal in archiver - CVE-2019-10743

 

Path traversal in archiver - CVE-2019-10743

Published: July 5, 2023


Vulnerability identifier: #VU77963
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10743
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A local attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

archiver
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data

How to mitigate CVE-2019-10743

Install updates from vendor's website.

archiver - update to 3.3.2

External References

Related Security Bulletins