CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
29.5%
IBM MQ Appliance has resolved a cross-site request forgery vulnerability.
CVEID:CVE-2022-31773
**DESCRIPTION:**IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/228357 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM MQ Appliance | 9.2 CD |
IBM MQ Appliance | 9.2 LTS |
This vulnerability is addressed under IT41915
IBM strongly recommends addressing the vulnerability now.
IBM MQ Appliance version 9.2 LTS
Apply Fixpack 9.2.0.7, or later firmware.
IBM MQ Appliance version 9.2 CD
Apply 9.2.5 CD CSU04 or later firmware.
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | mq_appliance | 9.2.0.0 | cpe:2.3:a:ibm:mq_appliance:9.2.0.0:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.1 | cpe:2.3:a:ibm:mq_appliance:9.2.0.1:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.2 | cpe:2.3:a:ibm:mq_appliance:9.2.0.2:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.3 | cpe:2.3:a:ibm:mq_appliance:9.2.0.3:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.4 | cpe:2.3:a:ibm:mq_appliance:9.2.0.4:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.5 | cpe:2.3:a:ibm:mq_appliance:9.2.0.5:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.0.6 | cpe:2.3:a:ibm:mq_appliance:9.2.0.6:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.1 | cpe:2.3:a:ibm:mq_appliance:9.2.1:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.2 | cpe:2.3:a:ibm:mq_appliance:9.2.2:*:*:*:*:*:*:* |
ibm | mq_appliance | 9.2.3 | cpe:2.3:a:ibm:mq_appliance:9.2.3:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
29.5%