Path traversal in LED Assistant - CVE-2023-4613
Published: February 27, 2024
Vulnerability identifier: #VU86817
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4613
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the /api/settings/upload endpoint. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
LED Assistant
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
How to mitigate CVE-2023-4613
Install update from vendor's website.
LED Assistant - update to 2.1.57
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2