Lucene search

K
ibmIBM06FBD4D5E2F2CF4CA845EB7D845DF53D01619E2DDED68F08373FA140213E59E3
HistoryMar 02, 2023 - 8:39 p.m.

Security Bulletin: There is a security vulnerability in Apache SOAP used by IBM Maximo Manage application in IBM Maximo Application Suite (CVE-2022-40705)

2023-03-0220:39:44
www.ibm.com
58
apache soap
ibm maximo manage
xml external entity injection
cve-2022-40705
ibm maximo application suite
security vulnerability
vulnerability patch fix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.6%

Summary

There is a security vulnerability in Apache SOAP used by IBM Maximo Manage application in IBM Maximo Application Suite.

Vulnerability Details

CVEID:CVE-2022-40705
**DESCRIPTION:**Apache SOAP is vulnerable to an XML external entity injection (XXE) attack when processing XML data, caused by a weakly configured XML parser in RPCRouterServlet. By using specially-crafted XML content in the configuration file, a remote attacker could exploit this vulnerability to read arbitrary files.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/236814 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Product versions affected:

Affected Product(s) Version(s)
Maximo Manage Application in IBM Maximo Application Suite MAS 8.8-Manage 8.4

Remediation/Fixes

For IBM Maximo Manage application in IBM Maximo Application Suite:

MAS Manage Patch Fix or Release
8.8 8.4.5 or latest (available from the Catalog under Update Available)
8.9 8.5 or latest (available from the Catalog under Update Available)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch8.8.0
VendorProductVersionCPE
ibmmaximo_application_suite8.8.0cpe:2.3:a:ibm:maximo_application_suite:8.8.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.6%

Related for 06FBD4D5E2F2CF4CA845EB7D845DF53D01619E2DDED68F08373FA140213E59E3