Incorrect authorization in Ree6 - CVE-2022-39302
Published: February 28, 2024
Vulnerability details
The vulnerability allows a remote user to bypass security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can send a specifically crafted log message to the application to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target.
Affected software
IBM Watson Machine Learning Accelerator
How to mitigate CVE-2022-39302
IBM Watson Machine Learning Accelerator - update to 3.0.0