Lucene search

K
ibmIBM4D7D6CE6B9BA698BFB9B758C15E38ED5972AE720478AC2AAD2A202C6748BA969
HistoryApr 21, 2022 - 9:59 a.m.

Security Bulletin: Vulnerability in Apache Log4j affects IBM Integrated Analytics System.

2022-04-2109:59:10
www.ibm.com
113

0.005 Low

EPSS

Percentile

77.5%

Summary

Apache Log4j used by IBM Integrated Analytics System. IBM Integrated Analytics System has addressed the applicable CVE(CVE-2022-23302).

Vulnerability Details

CVEID:CVE-2022-23302
**DESCRIPTION:**Apache Log4j could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in JMSSink. By sending specially-crafted JNDI requests using TopicConnectionFactoryBindingName configuration, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/217460 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Integrated Analytics System 1.0.0-1.0.27.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying below security patch.

Product VRMF Remediation / First Fix
IBM Integrated Analytics System 7.9.22.01.SP7 Link to fix central

Please follow the steps given in release notes to upgrade system with security patches

Workarounds and Mitigations

None

VendorProductVersionCPE
ibmsmart_analytics_system_5600*cpe:2.3:h:ibm:smart_analytics_system_5600:*:*:*:*:*:*:*:*
ibmsmart_analytics_system_5600*cpe:2.3:h:ibm:smart_analytics_system_5600:*:*:*:*:*:*:*:*