CVE-2023-46169
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X-Force ID: 269406.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.06%
- CWE
- CWE-41
- Published
- 2024-03-07
- Last modified
- 2026-03-13
Affected products
- IBM DS8900F
Weakness type
Related vulnerabilities
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2025-24470 — An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.
- CVE-2022-0855 — Improper Resolution of Path Equivalence in microweber-dev/whmcs_plugin
- CVE-2024-8765 — Improper Path Equivalence Resolution in lunary-ai/lunary
- CVE-2026-57441 — MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
- CVE-2026-5816 — Improper Resolution of Path Equivalence in GitLab
- CVE-2026-72835 — filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
- CVE-2026-34451 — Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories