IBM Cloud Pak System Directory Traversal Vulnerability Allowing Arbitrary File Access

Vulnerability

A directory traversal vulnerability has been identified in IBM Cloud Pak System versions 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0. This vulnerability could allow remote attackers to traverse directories on the system by sending specially crafted URL requests that include 'dot dot' sequences. Exploitation of this vulnerability could lead to unauthorized access to arbitrary files on the system.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive files on the system, potentially leading to further attacks.

Remediation

Users of IBM Cloud Pak System on Intel should upgrade to version 2.3.4.1, available through IBM Fix Central. For Power users, version 2.3.5.0 is recommended, also available through IBM Fix Central/Passport Advantage Online. Instructions for upgrading can be found on the IBM Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.