Path traversal in uimaj - CVE-2022-32287
Published: May 15, 2024
Vulnerability identifier: #VU89531
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32287
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists in a FileUtil class used by the PEAR management component of Apache UIMAs. A remote attacker can create files outside the designated target directory using carefully crafted ZIP entry names.
Affected software
uimaj
IBM Watson Assistant for IBM Cloud Pak for Data
Datacap
Robotic Process Automation for Cloud Pak
IBM Watson Assistant for IBM Cloud Pak for Data
Datacap
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2022-32287
Install updates from vendor's website.
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Datacap - update to 9.1.10
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.2
Datacap - update to 9.1.10
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.2