Impact
IBM Cloud Pak for Data 5.1.2 allows a remote attacker to traverse directories and read arbitrary files on the underlying system. By sending a URL that contains "../" sequences, the application fails to properly validate or sanitize the path component, enabling access to files outside the intended directory. This weakness can lead to disclosure of confidential configuration files, logs, or other sensitive data, and may facilitate further attacks if such files contain credentials or code that could be executed.
Affected Systems
IBM Cloud Pak for Data version 5.1.2 is the affected product. The vendor’s fix is available in version 5.2.2 and later.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high impact. An attacker can trigger the flaw by issuing a crafted HTTP request over the network, without requiring additional privileges or user interaction. Although the EPSS score of < 1% indicates a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, the ability to read arbitrary files poses a significant confidentiality risk. The attack vector is network-based and the flaw can be exercised by anyone able to reach the vulnerable endpoint, making the exploitation path straightforward.
OpenCVE Enrichment