Lucene search

K
ibmIBM527E0CC57F14F408B6531907A68CCE933694BD24D4E21312D391EF437C2BCA34
HistorySep 26, 2022 - 6:30 p.m.

Security Bulletin: Multiple security vulnerabilities have been identified in IBM WebSphere Application Server, which is a required product for IBM Tivoli Netcool Configuration Manager.

2022-09-2618:30:56
www.ibm.com
26
ibm tivoli netcool configuration manager
ibm websphere application server
security vulnerabilities
cve-2022-28614
cve-2022-28615
cve-2022-29404
cve-2022-26377
cve-2022-31813
cve-2022-30556
ibm http server

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.024

Percentile

90.2%

Summary

IBM WebSphere Application Server is a required product for IBM Tivoli Netcool Configuration Manager version 6.4.2. Information about multiple security vulnerabilities(CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-26377, CVE-2022-31813, CVE-2022-30556) affecting IBM WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
ITNCM 6.4.2

Remediation/Fixes

Affected Product(s) Version(s) Remediation
ITNCM 6.4.2

Multiple vulnerabilities in IBM HTTP Server used by IBM WebSphere Application Server

See section: For V8.5.0.0 through 8.5.5.21:

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_netcool_security_managerMatch6.4.2
VendorProductVersionCPE
ibmtivoli_netcool_security_manager6.4.2cpe:2.3:a:ibm:tivoli_netcool_security_manager:6.4.2:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.024

Percentile

90.2%