Lucene search

K
ibmIBM7D4C0F2B2FAF87DA52AD11C887F8B0C970625C9C8CD75680611C0853C6C408AF
HistoryJan 17, 2024 - 11:48 a.m.

Security Bulletin: IBM App Connect Enterprise Toolkit & IBM Integration Bus Toolkit are vulnerable to a remote attacker due to Apache Derby. (CVE-2022-46337)

2024-01-1711:48:27
www.ibm.com
10
ibm
remote attacker
apache derby
vulnerability
ldap injection
cvss
fix
apar
ibm app connect enterprise
ibm integration bus
cve-2022-46337

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

62.3%

Summary

IBM App Connect Enterprise Toolkit & IBM Integration Bus Toolkit are vulnerable to a remote attacker due to Apache Derby, which affects the Derby Sample Database in the toolkit. This bulletin identifies the steps to take to address the vulnerability.

Vulnerability Details

CVEID:CVE-2022-46337
**DESCRIPTION:**Apache Derby could allow a remote attacker to bypass security restrictions, caused by a LDAP injection vulnerability in authenticator. By sending a specially crafted request, an attacker could exploit this vulnerability to view and corrupt sensitive data and run sensitive database functions and procedures.
CVSS Base score: 9.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/271915 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.11.0
IBM App Connect Enterprise 11.0.0.1 - 11.0.0.24
IBM Integration Bus 10.1 - 10.1.0.2

Remediation/Fixes

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Toolkit and IBM Integration Bus Toolkit

Affected Product(s) Version(s) APAR Remediation / Fixes
IBM App Connect Enterprise 12.0.1.0 - 12.0.11.0 IT45139

The APAR (IT45139) is available from

IBM App Connect Enterprise v12 - Fix Pack 12.0.11.1

IBM App Connect Enterprise| 11.0.0.1 - 11.0.0.24| IT45139| Interim Fix for APAR (IT45139) is available to apply to 11.0.0.24 from

IBM Fix Central
IBM Integration Bus| 10.1 - 10.1.0.2| IT45139| Interim Fix for APAR (IT45139) is available to apply to 10.1.0.2 from

IBM Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.11.0
OR
ibmapp_connect_enterpriseRange11.0.0.1
OR
ibmapp_connect_enterpriseRange11.0.0.24
OR
ibmintegration_busRange10.1
OR
ibmintegration_busRange10.1.0.2

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

62.3%

Related for 7D4C0F2B2FAF87DA52AD11C887F8B0C970625C9C8CD75680611C0853C6C408AF