Rewterz
Rewterz Threat Advisory – CVE-2022-41296 – IBM Db2U Vulnerability
December 2, 2022
Rewterz
Rewterz Threat Alert – STRRAT Malware – Active IOCs
December 2, 2022

Rewterz Threat Advisory – Multiple IBM WebSphere Automation Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-43900 CVSS:5.3
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system.

CVE-2022-43901 CVSS:5.7
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components

Impact

  • Security Bypass
  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-43900
  • CVE-2022-43901

Affected Vendors

IBM

Affected Products

  • IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2

Remediation

Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.

IBM Security Bulletin