Executive brief
IBM InfoSphere Optim Test Data Fabrication, a tool used to create high-quality synthetic data for software testing, is vulnerable to a security flaw that allows unauthorized access to system files. A remote attacker can exploit this to read sensitive configuration files or other data stored on the server. This could lead to the exposure of credentials or intellectual property, potentially compromising the integrity of the testing environment.
Technical details
A path traversal vulnerability (CWE-22) exists in the Resource Manager component of IBM InfoSphere Optim Test Data Fabrication. The application fails to properly sanitize user-supplied input in URL requests, allowing an unauthenticated remote attacker to use 'dot dot' (/../) sequences to escape the intended directory. By sending a specially crafted URL, an attacker can read arbitrary files on the underlying operating system with the privileges of the application process. No user interaction is required for exploitation. IBM recommends contacting technical support for specific workarounds and resolution instructions.
Affected products
- IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7
Timeline
- 2026-05-12: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date