Impact
IBM Documentation Offline versions 1.0.0 through 1.4.1 include an improper limitation of a pathname that allows a remote attacker to read arbitrary files inside the installation directory, which can lead to information disclosure. The vulnerability is classified as CWE‑22 (Path Traversal). The information disclosure exposed by reading files may enable further exploitation such as session forgery or remote code execution as noted in the advisory title.
Affected Systems
The affected product is IBM Documentation Offline. All releases from 1.0.0 through 1.4.1 are vulnerable; the company recommends upgrading to the latest available release, 1.5.1.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this flaw, and a remote attacker can exploit it without any local access. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw is reachable via network, it can be triggered by unauthenticated remote requests and causes a loss of confidentiality, potentially leading to session compromise or code execution.
OpenCVE Enrichment