Lucene search

K
ibmIBM6F029265D5F1E4EA73E465DA5F623E94E637B58AB0899CCF62C2946F8619AFEF
HistoryFeb 01, 2023 - 5:59 a.m.

Security Bulletin: App Connect Professional is affected by JsonErrorReportValve in Apache Tomcat.

2023-02-0105:59:16
www.ibm.com
29
app connect professional
jsonerrorreportvalve
apache tomcat
vulnerability
cve-2022-45143
security
fix
7.5.5.0

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.6%

Summary

App Connect Professional have addressed the JsonErrorReportValve vulnerability reported in Apache Tomcat.

Vulnerability Details

CVEID:CVE-2022-45143
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by not escape the type, message or description values in the JsonErrorReportValve function. By sending a specially-crafted request, an attacker could exploit this vulnerability to supply values that invalidated or manipulated the JSON output.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/243565 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Professional v755

Remediation/Fixes

_ Product_ _ VRMF_ _ APAR_ _ Remediation/First Fix_
App Connect Professional 7.5.5.0 LI82862 7550 Fixcentral link

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_professionalMatch755
OR
ibmapp_connect_professionalMatch018
VendorProductVersionCPE
ibmapp_connect_professional755cpe:2.3:a:ibm:app_connect_professional:755:*:*:*:*:*:*:*
ibmapp_connect_professional018cpe:2.3:a:ibm:app_connect_professional:018:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.6%