Path traversal in uimaj - CVE-2022-32287

 

Path traversal in uimaj - CVE-2022-32287

Published: May 15, 2024


Vulnerability identifier: #VU89531
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32287
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists in a FileUtil class used by the PEAR management component of Apache UIMAs. A remote attacker can create files outside the designated target directory using carefully crafted ZIP entry names.


Affected software

uimaj
IBM Watson Assistant for IBM Cloud Pak for Data
Datacap
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2022-32287

Install updates from vendor's website.

IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Datacap - update to 9.1.10
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.2

External References

Related Security Bulletins