Home » Database

AVID-2026-R1118

Description

IBM Cloud Pak for Data file upload (CVE-2022-36769)

Details

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product’s environment. IBM X-Force ID: 232034.

Reason for inclusion in AVID: The CVE describes a vulnerability in IBM Cloud Pak for Data that allows a privileged user to upload malicious files which can be automatically processed within the product. Cloud Pak for Data is a platform used to manage data and run AI workflows, so the issue directly affects the AI stack and its supply chain. It is a software vulnerability with potential code execution and data/process integrity impacts, and the report provides explicit details (CVE ID, CWE-77, impact metrics) sufficient for AVID consideration.

References

Affected or Relevant Artifacts

  • Developer: IBM
  • Deployer: IBM
  • Artifact Details:
TypeName
SystemCloud Pak for Data

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score7.2
Base Severity🔴 High
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🔴 High
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-77CWE-77 Improper Neutralization of Special Elements used in a Command (‘Command Injection’)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-04-26
  • Version: 0.3.3
  • AVID Entry