Lucene search

K
ibmIBM5677C5C112695B6726E8E59857B6232B27D5BF25D5F811B29B939456F540C9C4
HistoryFeb 01, 2023 - 12:49 p.m.

Security Bulletin: IBM App Connect Enterprise is vulnerable to a remote authenticated attacker due to json5 (CVE-2022-46175)

2023-02-0112:49:14
www.ibm.com
17
ibm
app connect enterprise
remote code execution
vulnerability
fix
json5
cve-2022-46175
ibm fix central

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%

Summary

IBM App Connect Enterprise is vulnerable to a remote authenticated attacker executing arbitrary code due to json5 (CVE-2022-46175). The resolving fix includes json5 v2.2.3

Vulnerability Details

CVEID:CVE-2022-46175
**DESCRIPTION:**JSON5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw in the parse method. By adding or modifying properties of Object.prototype using a proto or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
CVSS Base score: 7.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/242965 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.7.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise

Product(s) Version(s) APAR Remediation / Fix
IBM App Connect Enterprise v12.0.1.0 - v12.0.7.0 IT42894

Interim fix for APAR (IT42894) is available in

IBM Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0โ‰ฅ
OR
ibmapp_connect_enterpriseRangeโ‰ค12.0.7.0

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.006 Low

EPSS

Percentile

77.9%