CVE Vulnerabilities

CVE-2023-35899

Improper Neutralization of Formula Elements in a CSV File

Published: Mar 21, 2024 | Modified: Mar 05, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 259354.

Weakness

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Affected Software

Name Vendor Start Version End Version
Cloud_pak_for_business_automation Ibm 18.0.0 (including) 18.0.0 (including)
Cloud_pak_for_business_automation Ibm 18.0.1 (including) 18.0.1 (including)
Cloud_pak_for_business_automation Ibm 18.0.2 (including) 18.0.2 (including)
Cloud_pak_for_business_automation Ibm 19.0.1 (including) 19.0.1 (including)
Cloud_pak_for_business_automation Ibm 19.0.2 (including) 19.0.2 (including)
Cloud_pak_for_business_automation Ibm 19.0.3 (including) 19.0.3 (including)
Cloud_pak_for_business_automation Ibm 20.0.1 (including) 20.0.1 (including)
Cloud_pak_for_business_automation Ibm 20.0.2 (including) 20.0.2 (including)
Cloud_pak_for_business_automation Ibm 20.0.3 (including) 20.0.3 (including)
Cloud_pak_for_business_automation Ibm 21.0.1 (including) 21.0.1 (including)
Cloud_pak_for_business_automation Ibm 21.0.2 (including) 21.0.2 (including)
Cloud_pak_for_business_automation Ibm 21.0.3 (including) 21.0.3 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_001 (including) 21.0.3-interim_fix_001 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_002 (including) 21.0.3-interim_fix_002 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_003 (including) 21.0.3-interim_fix_003 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_004 (including) 21.0.3-interim_fix_004 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_005 (including) 21.0.3-interim_fix_005 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_006 (including) 21.0.3-interim_fix_006 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_007 (including) 21.0.3-interim_fix_007 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_008 (including) 21.0.3-interim_fix_008 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_009 (including) 21.0.3-interim_fix_009 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_010 (including) 21.0.3-interim_fix_010 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_011 (including) 21.0.3-interim_fix_011 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_012 (including) 21.0.3-interim_fix_012 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_013 (including) 21.0.3-interim_fix_013 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_014 (including) 21.0.3-interim_fix_014 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_015 (including) 21.0.3-interim_fix_015 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_016 (including) 21.0.3-interim_fix_016 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_017 (including) 21.0.3-interim_fix_017 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_018 (including) 21.0.3-interim_fix_018 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_019 (including) 21.0.3-interim_fix_019 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_020 (including) 21.0.3-interim_fix_020 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_021 (including) 21.0.3-interim_fix_021 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_022 (including) 21.0.3-interim_fix_022 (including)
Cloud_pak_for_business_automation Ibm 21.0.3-interim_fix_023 (including) 21.0.3-interim_fix_023 (including)
Cloud_pak_for_business_automation Ibm 22.0.1 (including) 22.0.1 (including)
Cloud_pak_for_business_automation Ibm 22.0.2 (including) 22.0.2 (including)
Cloud_pak_for_business_automation Ibm 23.0.1 (including) 23.0.1 (including)
Cloud_pak_for_business_automation Ibm 23.0.1-interim_fix_001 (including) 23.0.1-interim_fix_001 (including)

Potential Mitigations

References