Impact
IBM Documentation Offline versions 1.0.0 to 1.4.1 suffer from improper output neutralization in log handling, a flaw classified as CWE-117, which allows a remote attacker to execute arbitrary code. The vulnerability also raises the risk of information disclosure and session forgery as indicated by the product title. Successful exploitation could compromise the host system, leaking data, hijacking sessions, or installing persistence mechanisms. The CVSS score of 8.8 indicates a high severity level for these possible outcomes.
Affected Systems
The affected product is IBM Documentation Offline, with vulnerable releases ranging from 1.0.0 through 1.4.1. All installations of these versions should be verified and, if present, upgraded to the latest release, 1.5.1, which includes the necessary fix.
Risk and Exploitability
The CVSS score reflects a high impact, but the EPSS score is not available, so the estimated likelihood of exploitation remains unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed public exploit at this time. The likely attack vector is remote, leveraging crafted log entries that bypass proper output sanitization to inject malicious content. With sufficient privileges to trigger log writing or to access the application, an attacker could trigger code execution.
OpenCVE Enrichment