Lucene search

K
ibmIBM580B99132BA6765B368771674D4F7069792D32AE96669CA48218D57B6ACA3D28
HistoryMay 04, 2023 - 8:25 p.m.

Security Bulletin: IBM Cognos Command Center is vulnerable to a remote code execution vulnerability in Apache Commons Text (CVE-2022-42889)

2023-05-0420:25:47
www.ibm.com
7
ibm cognos command center
remote code execution
apache commons text
cve-2022-42889
vulnerability
upgrade fix pack

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%

Summary

A remote code execution vulnerability in Apache Commons Text used by IBM Cognos Command Center was addressed.

Vulnerability Details

CVEID:CVE-2022-42889
**DESCRIPTION:**Apache Commons Text could allow a remote attacker to execute arbitrary code on the system, caused by an insecure interpolation defaults flaw. By sending a specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: <https://exchange.xforce.ibmcloud.com/vulnerabilities/238560&gt; for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cognos Command Center 10.2.4.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading.

Affected Product(s) Version Fix
IBM Cognos Command Center 10.2.4.1 Cognos Command Center 10.2.4 Fix Pack 1 IF17 available for download

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcognos_command_centerMatch10.2.4.1
CPENameOperatorVersion
cognos command centereq10.2.4.1

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.972 High

EPSS

Percentile

99.8%