Lucene search

K
ibmIBM775D8920A06E5F5CC834DDA404C4673AEF466A8D02F754107379066E0186B27F
HistoryJan 03, 2023 - 9:05 a.m.

Security Bulletin: Automation Assets in IBM Cloud Pak for Integration is vulnerable to remote code execution due to xmldom vulnerability [CVE-2022-37616]

2023-01-0309:05:49
www.ibm.com
48
ibm cloud pak for integration
automation assets
vulnerability
remote code execution
xmldom
cve-2022-37616
cvss base 9.8
prototype pollution
upgrade
operator upgrade.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

69.2%

Summary

Automation Assets in IBM Cloud Pak for Integration is vulnerable to remote code execution due to xmldom vulnerability with details below. [CVE-2022-37616] This vulnerability has been addressed.

Vulnerability Details

CVEID:CVE-2022-37616
**DESCRIPTION:**xmldom could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution in the dom.js script. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/238439 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Automation Assets in IBM Cloud Pak for Integration (CP4I) 2020.4.1
2021.1.1
2021.2.1
2021.4.1
2022.2.1

Remediation/Fixes

IBM strongly suggests the following remediation / fix:

Automation Assets version 2020.4.1, 2021.1, 2021.2,** 2021.4, or 2022.2 in IBM Cloud Pak for Integration**

Upgrade Automation Assets Operator to 2022.2.1-4 using the Operator upgrade process described in the IBM Documentation

<https://www.ibm.com/docs/en/cloud-paks/cp-integration/2022.2?topic=capabilities-upgrading-automation-assets&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_automationMatch2020.4.12021.1.12021.2.12021.4.12022.2.1
VendorProductVersionCPE
ibmcloud_pak_for_automation2020.4.12021.1.12021.2.12021.4.12022.2.1cpe:2.3:a:ibm:cloud_pak_for_automation:2020.4.12021.1.12021.2.12021.4.12022.2.1:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

69.2%

Related for 775D8920A06E5F5CC834DDA404C4673AEF466A8D02F754107379066E0186B27F