Lucene search

K
cveIbmCVE-2022-22486
HistoryFeb 03, 2023 - 12:15 a.m.

CVE-2022-22486

2023-02-0300:15:09
CWE-611
ibm
web.nvd.nist.gov
38
ibm
tivoli
workload scheduler
9.4
9.5
10.1
xml
external entity injection
xxe
attack
vulnerability
remote
memory resources
information security

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.002

Percentile

52.6%

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328.

Affected configurations

Nvd
Vulners
Node
ibmtivoli_workload_schedulerMatch9.4
OR
ibmtivoli_workload_schedulerMatch9.5
OR
ibmtivoli_workload_schedulerMatch10.1
VendorProductVersionCPE
ibmtivoli_workload_scheduler9.4cpe:2.3:a:ibm:tivoli_workload_scheduler:9.4:*:*:*:*:*:*:*
ibmtivoli_workload_scheduler9.5cpe:2.3:a:ibm:tivoli_workload_scheduler:9.5:*:*:*:*:*:*:*
ibmtivoli_workload_scheduler10.1cpe:2.3:a:ibm:tivoli_workload_scheduler:10.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Tivoli Workload Scheduler",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "9.4, 9.5, 10.1"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.002

Percentile

52.6%

Related for CVE-2022-22486