Lucene search

K
ibmIBM4F035FC8C564F24DC27D7F872B6D412B2702F0A84713898900DBD1CCB3855C3B
HistoryDec 16, 2022 - 5:09 p.m.

Security Bulletin: Vulnerability in IBM WebSphere Application Server (CVE-2022-35282) shipped with IBM Workload Scheduler 9.4

2022-12-1617:09:09
www.ibm.com
12
ibm workload scheduler
ibm websphere application server
vulnerability
server-side request forgery

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%

Summary

IBM WebSphere Application Server (WAS) is shipped as a component of IBM Workload Scheduler, which results in IBM Workload Scheduled being impacted by this vulnerability. IBM WebSphere Application Server is vulnerable to a server-side request forgery vulnerability. This has been addressed.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Workload Scheduler 9.4

Remediation/Fixes

Refer to the following security bulletin for vulnerability details and information about fixes addressed by IBM WebSphere Application Server (WAS) which is shipped with IBM Workload Scheduler. IBM recommends that these remediations are applied to all instances of IBM Workload Scheduler.

<https://www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-vulnerable-server-side-request-forgery-cve-2022-35282&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmworkload_schedulerMatch9.4
VendorProductVersionCPE
ibmworkload_scheduler9.4cpe:2.3:a:ibm:workload_scheduler:9.4:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%

Related for 4F035FC8C564F24DC27D7F872B6D412B2702F0A84713898900DBD1CCB3855C3B