Lucene search

K
ibmIBM1DD81F6090DA9F6475BD1C26FC14A0461F0FE89B932693BFB7D1E67A228D5372
HistoryOct 13, 2023 - 6:27 a.m.

Security Bulletin: The IBM® Engineering Lifecycle Engineering displays sensitive Information on ADMIN page (CVE-2022-34355).

2023-10-1306:27:55
www.ibm.com
37
ibm engineering lifecycle
sensitive information
admin page
cve-2022-34355
clm 6.0.6.1
ifix027
clm 6.0.6
ifix028
elm 7.0
ifix017
elm 7.0.1
ifix018
elm 7.0.2
ifix016

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Summary

Application displays Sensitive Information related to the backend technologies like JVM, DB Version, Application Server on ADMIN page.

Vulnerability Details

CVEID:CVE-2022-34355
**DESCRIPTION:**IBM Jazz Foundation could disclose sensitive version information to a user that could be used in further attacks against the system.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/230498 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
CLM 6.0.6.1
CLM 6.0.6
ELM 7.0.2
ELM 7.0
ELM 7.0.1

Remediation/Fixes

Affected Product(s) Version(s) Remediation/Fix/Instructions
CLM 6.0.6.1 Download and install iFix027 or later
CLM 6.0.6 Download and install iFix028 or later
ELM 7.0 Download and install iFix017 or later
ELM 7.0.1 Download and install iFix018 or later
ELM 7.0.2 Download and install iFix016 or later

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_engineering_lifecycle_management_baseMatch6.0.6.1
OR
ibmibm_engineering_lifecycle_management_baseMatch6.0.6
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0.1
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0.2
VendorProductVersionCPE
ibmibm_engineering_lifecycle_management_base6.0.6.1cpe:2.3:a:ibm:ibm_engineering_lifecycle_management_base:6.0.6.1:*:*:*:*:*:*:*
ibmibm_engineering_lifecycle_management_base6.0.6cpe:2.3:a:ibm:ibm_engineering_lifecycle_management_base:6.0.6:*:*:*:*:*:*:*
ibmibm_engineering_lifecycle_management_base7.0cpe:2.3:a:ibm:ibm_engineering_lifecycle_management_base:7.0:*:*:*:*:*:*:*
ibmibm_engineering_lifecycle_management_base7.0.1cpe:2.3:a:ibm:ibm_engineering_lifecycle_management_base:7.0.1:*:*:*:*:*:*:*
ibmibm_engineering_lifecycle_management_base7.0.2cpe:2.3:a:ibm:ibm_engineering_lifecycle_management_base:7.0.2:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Related for 1DD81F6090DA9F6475BD1C26FC14A0461F0FE89B932693BFB7D1E67A228D5372