Lucene search

K
ibmIBMB984973BD0499B5AC500C58359FE25956005D42A2BAD55BF778E60DA7566BDDD
HistoryNov 29, 2022 - 5:05 p.m.

Security Bulletin: IBM Sterling Connect:Direct Web Services is vulnerable to remote authenticated attacker to execute arbitrary code on the system due to PostgreSQL (CVE-2022-2625)

2022-11-2917:05:13
www.ibm.com
12
ibm sterling connect:direct web services
postgresql
vulnerability fix
remote authenticated attacker
arbitrary code
system
cve-2022-2625

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.4%

Summary

IBM Sterling Connect:Direct Web Services has addressed an applicable issue from PostgreSQL.

Vulnerability Details

CVEID:CVE-2022-2625
**DESCRIPTION:**PostgreSQL could allow a remote authenticated attacker to execute arbitrary code on the system, caused by improper control of the modification of dynamically-determined object attributes. By creating a specially-crafted object using at least one schema, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 7.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/233970 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Sterling Connect Direct Web Services 1.0
IBM Sterling Connect:Direct Web Services 6.0
IBM Sterling Connect:Direct Web Services 6.1

Remediation/Fixes

Product(s)|Version(s)|**Remediation
**
—|—|—
IBM Sterling Connect:Direct Web Services| 1.0| Apply 6.0.0.11, available on Fix Central
IBM Sterling Connect:Direct Web Services| 6.0| Apply 6.0.0.11, available on Fix Central
IBM Sterling Connect:Direct Web Services| 6.1| Apply 6.1.0.15, available on Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsterling_connect\Matchdirect6.0

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.4%