Lucene search

K
ibmIBM5BEB72C2B5C70EC83018F4A968C727C635D885DCAF8D47EFCC7E062314F19CCB
HistoryJul 12, 2023 - 8:26 a.m.

Security Bulletin: IBM Cloud Pak for Data Affected by Malicious File Upload Vulnerability (CVE-2022-36769)

2023-07-1208:26:36
www.ibm.com
16
ibm cloud pak for data
vulnerability
malicious file upload
privileged user
ibm watson knowledge catalog
remediation
jdbc drivers
auditable messages

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.3%

Summary

IBM Cloud Pak for Data could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product’s. This vulnerability has been addressed.

Vulnerability Details

CVEID:CVE-2022-36769
**DESCRIPTION:**IBM Cloud Pak for Data could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product’s environment.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/232034 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Knowledge Catalog on-prem 4.x

Remediation/Fixes

Install IBM Cloud Pak for Data 4.6.4 or higher

IBM Cloud Pak for Data 4.6.4 and above limits or restricts JDBC drivers uploads to certain set of users. For instance, admin user or user with “Administrator” role can upload JDBC drivers. An administrator role has “Administer platform” permissions. This permission is required to upload JDBC drivers. Additionally, users with “Platform administration” role will be able to upload JDBC drivers. Platform administration role has “Administer platform” and “Manage configurations” permissions. “Manage Configuration” permission is more granular. You can revoke this permission from users that do not require JDBC driver upload ability.

Additionally, IBM Cloud Pak for Data implemented new auditable messages that can be used to monitor and track JDBC driver upload activities.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmcloud_pak_for_dataMatchany
VendorProductVersionCPE
ibmcloud_pak_for_dataanycpe:2.3:a:ibm:cloud_pak_for_data:any:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.3%

Related for 5BEB72C2B5C70EC83018F4A968C727C635D885DCAF8D47EFCC7E062314F19CCB