6.5

CVE-2022-22353

IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.

Data is provided by the National Vulnerability Database (NVD)
IbmBig Sql Version7.1.0
   ClouderaData Platform Version7.1.3
   ClouderaData Platform Version7.1.4
   ClouderaData Platform Version7.1.5
   ClouderaData Platform Version7.1.7
IbmBig Sql Version7.1.1
   IbmCloud Pak For Data Version3.5 Update-
   IbmCloud Pak For Data Version3.5 Updaterefresh_1
   IbmCloud Pak For Data Version3.5 Updaterefresh_9
IbmBig Sql Version >= 7.2.0 <= 7.2.3
   IbmCloud Pak For Data Version4.0 Update-
   IbmCloud Pak For Data Version4.0 Updaterefresh_1
   IbmCloud Pak For Data Version4.0 Updaterefresh_3
IbmBig Sql Version7.2.3
   IbmCloud Pak For Data Version4.0 Updaterefresh_4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.309
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
psirt@us.ibm.com 5.3 1.6 3.6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N