5.5

CVE-2022-22423

IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Common Cryptographic Architecture SwEdition mtm_for_4767 Version >= 5.0.0 < 5.7.12
   Ibm ≫ Aix Version -
   Ibm ≫ I Version -
   Linux ≫ Linux Kernel Version -
Ibm ≫ Common Cryptographic Architecture SwEdition mtm_for_4769 Version >= 7.0.0 < 7.3.44
   Ibm ≫ Aix Version -
   Ibm ≫ I Version -
   Ibm ≫ Powerlinux Version -
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.164
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
IBM 6.5 2 4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://exchange.xforce.ibmcloud.com/vulnerabilities/223596
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/6695893
Patch
Vendor Advisory