Lucene search

K
cveIbmCVE-2022-35279
HistoryNov 03, 2022 - 8:15 p.m.

CVE-2022-35279

2022-11-0320:15:28
CWE-312
ibm
web.nvd.nist.gov
45
2
ibm
business automation
workflow
cve-2022-35279
nvd
security
vulnerability
ibm x-force
230537

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

19.7%

“IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537.”

Affected configurations

Nvd
Vulners
Node
ibmbusiness_automation_workflowRange18.0.0.018.0.0.2traditional
OR
ibmbusiness_automation_workflowRange19.0.0.019.0.0.3traditional
OR
ibmbusiness_automation_workflowMatch20.0.0.1traditional
OR
ibmbusiness_automation_workflowMatch20.0.0.1-containers
OR
ibmbusiness_automation_workflowMatch20.0.0.2traditional
OR
ibmbusiness_automation_workflowMatch20.0.0.2-containers
OR
ibmbusiness_automation_workflowMatch21.0.1traditional
OR
ibmbusiness_automation_workflowMatch21.0.2traditional
OR
ibmbusiness_automation_workflowMatch21.0.2-containers
OR
ibmbusiness_automation_workflowMatch21.0.3traditional
OR
ibmbusiness_automation_workflowMatch21.0.3if002containers
OR
ibmbusiness_automation_workflowMatch21.0.3if005containers
OR
ibmbusiness_automation_workflowMatch21.0.3if006containers
OR
ibmbusiness_automation_workflowMatch21.0.3if007containers
OR
ibmbusiness_automation_workflowMatch21.0.3if008containers
OR
ibmbusiness_automation_workflowMatch21.0.3if009containers
OR
ibmbusiness_automation_workflowMatch21.0.3if010containers
OR
ibmbusiness_automation_workflowMatch21.0.3if011containers
OR
ibmbusiness_automation_workflowMatch22.0.1traditional
OR
ibmbusiness_automation_workflowMatch22.0.1-containers
OR
ibmbusiness_automation_workflowMatch22.0.1if001containers
VendorProductVersionCPE
ibmbusiness_automation_workflow*cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow20.0.0.1cpe:2.3:a:ibm:business_automation_workflow:20.0.0.1:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow20.0.0.1cpe:2.3:a:ibm:business_automation_workflow:20.0.0.1:-:*:*:containers:*:*:*
ibmbusiness_automation_workflow20.0.0.2cpe:2.3:a:ibm:business_automation_workflow:20.0.0.2:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow20.0.0.2cpe:2.3:a:ibm:business_automation_workflow:20.0.0.2:-:*:*:containers:*:*:*
ibmbusiness_automation_workflow21.0.1cpe:2.3:a:ibm:business_automation_workflow:21.0.1:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow21.0.2cpe:2.3:a:ibm:business_automation_workflow:21.0.2:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow21.0.2cpe:2.3:a:ibm:business_automation_workflow:21.0.2:-:*:*:containers:*:*:*
ibmbusiness_automation_workflow21.0.3cpe:2.3:a:ibm:business_automation_workflow:21.0.3:*:*:*:traditional:*:*:*
ibmbusiness_automation_workflow21.0.3cpe:2.3:a:ibm:business_automation_workflow:21.0.3:if002:*:*:containers:*:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "IBM Business Automation Workflow",
    "versions": [
      {
        "version": "\"18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1\"",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

19.7%

Related for CVE-2022-35279