IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HIBM Cloud Pak For Security
APPIbm1.3.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-25022CRITICAL9.6PL ✓same product
IBM QRadar Suite / Cloud Pak for Security: ujawnienie danych w plikach konfiguracyjnych
CVE-2021-20578CRITICAL9.8PL ✓same product
IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)
CVE-2021-20538CRITICAL9.1PL ✓same product
Nieprawidłowa autoryzacja w IBM Cloud Pak for Security
CVE-2025-25021HIGH7.2same product
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0...
CVE-2023-47726HIGH7.1same product
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21...