Impact
An unauthorized user can inject content into log files by exploiting an omission of neutralization for special characters. The flaw allows the user to alter the structure or content of log entries, potentially masking malicious actions or creating confusion during forensic analysis. This constitutes a log injection vulnerability (CWE-117) that can affect confidentiality, integrity, and the reliability of monitoring and auditing processes.
Affected Systems
IBM Cloud Pak for Data System version 11.3.0.2 through Interim Fix 001 are affected. The fix is provided in version 11.3.1.2-IF1-WS-ICPDS-NPS-Clients-fp326919.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is not available and the vulnerability is not catalogued in CISA KEV, the known exploitation probability is uncertain. Based on the description, the attack requires an unauthorized user with the ability to influence log data, which likely occurs in a local or web‑application context. Exploitation would enable log tampering but does not grant arbitrary code execution or direct system compromise.
OpenCVE Enrichment