Lucene search

K
cveIbmCVE-2022-22318
HistoryJun 20, 2022 - 5:15 p.m.

CVE-2022-22318

2022-06-2017:15:08
CWE-613
ibm
web.nvd.nist.gov
54
7
ibm
curam
social program management
security
vulnerability
authentication
impersonation
nvd
cve-2022-22318

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

51.1%

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Affected configurations

Nvd
Vulners
Node
ibmcuram_social_program_managementMatch8.0.0
OR
ibmcuram_social_program_managementMatch8.0.1
AND
hphp-uxMatch-
OR
ibmaixMatch-
OR
ibmz\/osMatch-
OR
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
OR
oraclesolarisMatch--
VendorProductVersionCPE
ibmcuram_social_program_management8.0.0cpe:2.3:a:ibm:curam_social_program_management:8.0.0:*:*:*:*:*:*:*
ibmcuram_social_program_management8.0.1cpe:2.3:a:ibm:curam_social_program_management:8.0.1:*:*:*:*:*:*:*
hphp-ux-cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
ibmaix-cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
ibmz\/os-cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
oraclesolaris-cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*

CNA Affected

[
  {
    "product": "Curam Social Program Management",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.0"
      },
      {
        "status": "affected",
        "version": "8.0.1"
      }
    ]
  }
]

Social References

More

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

51.1%

Related for CVE-2022-22318