Path traversal in archiver - CVE-2019-10743
Published: July 5, 2023
Vulnerability identifier: #VU77963
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10743
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
archiver
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
How to mitigate CVE-2019-10743
Install updates from vendor's website.
archiver - update to 3.3.2