Vulnerabilities > CVE-2022-43864 - Unspecified vulnerability in IBM Business Automation Workflow and Business Monitor
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 239427.
Vulnerable Configurations
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239427
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239427
- https://www.ibm.com/support/pages/node/6857223
- https://www.ibm.com/support/pages/node/6857223
- https://www.ibm.com/support/pages/node/6857239
- https://www.ibm.com/support/pages/node/6857239