Lucene search

K
ibmIBM29FE721AD7A4963438359EC095572AFEF72FE29D59BAFE257194EF35A48CEB4C
HistoryApr 12, 2022 - 6:08 p.m.

Security Bulletin: IBM Tivoli Netcool Impact is vulnerable to arbitrary code exection due to Apache Log4j (CVE-2022-23307)

2022-04-1218:08:45
www.ibm.com
15

0.008 Low

EPSS

Percentile

82.3%

Summary

IBM Tivoli Netcool Impact which includes the ActiveMQ package is vulnerable to arbitrary code exection due to Apache Log4j (CVE-2022-23307) . This has been addressed by updating ActiveMQ to version 5.16.4 which removes Apache Log4j v1 from ActiveMQ.

Vulnerability Details

CVEID:CVE-2022-23307
**DESCRIPTION:**Apache Log4j could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the in Apache Chainsaw component. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/217462 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli Netcool Impact 7.1.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading.

Product VRMF APAR Remediation
IBM Tivoli Netcool Impact 7.1.0 7.1.0.25 IJ37697 Upgrade to IBM Tivoli Netcool Impact 7.1.0 FP25

Workarounds and Mitigations

None

CPENameOperatorVersion
tivoli netcool/impacteq7.1.0