Apache Log4j v1 is shipped within the ActiveMQ package of IBM Tivoli Netcool Impact. This has been resolved by updating ActiveMQ to version 5.16.4 which removes log4j from ActiveMQ.
CVEID:CVE-2022-23305
**DESCRIPTION:**Apache Log4j is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the JDBCAppender, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/217461 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Tivoli Netcool Impact | 7.1.0 |
Product | VRMF | APAR | Remediation |
---|---|---|---|
IBM Tivoli Netcool Impact 7.1.0 | 7.1.0.25 | IJ37697 | Upgrade to IBM Tivoli Netcool Impact 7.1.0 FP25 |
None
CPE | Name | Operator | Version |
---|---|---|---|
tivoli netcool/impact | eq | 7.1.0 |