Impact
IBM Documentation Offline versions 1.0.0 through 1.4.1 contain a flaw that allows a remote attacker to execute arbitrary code by controlling file paths. The vulnerability is caused by improper neutralization of special elements used in file path handling, enabling path traversal or manipulation that can lead to the execution of malicious code on the host system. This flaw enables a complete compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
IBM Documentation Offline 1.0.0 to 1.4.1 are impacted. The affected versions are listed by IBM as from 1.0.0 through 1.4.1; the latest released version 1.5.1 contains the fix.
Risk and Exploitability
The CVSS score of 9.8 categorizes this vulnerability as critical, indicating a high likelihood of successful exploitation if the flaws are present. EPSS is currently not available, so a specific exploitation probability cannot be determined, but the lack of inclusion in the CISA KEV catalog does not diminish the risk. The likely attack vector is remote, as the flaw can be triggered through network-accessible inputs that control file paths. If exploited, an attacker can achieve full code execution on the host, effectively bypassing all security controls.
OpenCVE Enrichment