Lucene search

K
ibmIBM8E7237871A742825580B7203D4A90FA09D03933690AF2B1232B58632454A8EF5
HistoryJun 21, 2022 - 4:23 p.m.

Security Bulletin: IBM MQ Internet Pass-Thru is vulnerable to an issue within IBM® Runtime Environment Java™ Technology Edition, Version 7. (CVE-2022-21496)

2022-06-2116:23:48
www.ibm.com
9
ibm
mq
internet pass-thru
vulnerability
runtime environment
java technology edition
version 7
cve-2022-21496
websphere
affected product
solaris
upgrade
jre

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.002

Percentile

56.1%

Summary

IBM MQ Internet Pass-Thru has addressed the following vulnerability in the IBM® Runtime Environment Java™ Technology Edition, Version 7 used by IBM MQ Internet Pass-Thru.

Vulnerability Details

CVEID:CVE-2022-21496
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JNDI component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/224777 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM WebSphere Internet Pass-Thru 2.1

Remediation/Fixes

IBM WebSphere Internet Pass-Thru version 2.1 IBM strongly recommends that you address this vulnerability now by upgrading the MQIPT JRE to the latest available on the MS81: IBM MQ Internet Pass-Thru SupportPac page.

Note: This MQ IPT 2.1 JRE update is provided on Solaris platforms only, for users with appropriate extended support entitlement. Users of MQ IPT 2.1 on all other platforms should migrate to MQ IPT 9.2.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmqMatch2.1.0

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.002

Percentile

56.1%