VDB
CVE-2022-31772
CVE-2022-31772
PUBLISHED
CVSS 6.5 MEDIUM
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
EPSS 0.32% · 55.1th percentile
Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.32%
55.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | WebSphere | |
| IBM | Sterling | |
| n/a | n/a | * |
| ibm | mq | 9.0.0.0, 9.1.0.0, 8.0.0.0 |
Timeline
- Nov 11, 2022 CVE Published
- Nov 12, 2022 EPSS Score
- Dec 25, 2022 EPSS Score
- Feb 6, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 21, 2023 EPSS Score
- May 2, 2023 EPSS Score
- Jun 14, 2023 EPSS Score
- Jul 27, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 21, 2023 EPSS Score
- Oct 21, 2023 PoC Published
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/228335 technical
- https://www.ibm.com/support/pages/node/6833806 patch
- https://www.ibm.com/support/pages/node/6890669 advisory
- https://www.ibm.com/support/pages/node/6890665 advisory
- https://www.ibm.com/support/pages/node/6890663 advisory
- https://www.ibm.com/support/pages/node/6891111 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-31772 advisory
- https://github.com/sindresorhus/normalize-url/releases/tag/v6.0.1 url
- https://security.netapp.com/advisory/ntap-20210706-0001/ url