4.3
CVE-2022-35279
- EPSS 0.29%
- Veröffentlicht 03.11.2022 20:15:28
- Zuletzt bearbeitet 02.05.2025 21:15:17
- Erkennungen
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Business Automation Workflow SwEdition traditional Version >= 18.0.0.0 <= 18.0.0.2
Ibm ≫ Business Automation Workflow SwEdition traditional Version >= 19.0.0.0 <= 19.0.0.3
Ibm ≫ Business Automation Workflow Version 20.0.0.1 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 20.0.0.1 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 20.0.0.2 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 20.0.0.2 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.1 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 21.0.2 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 21.0.2 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if002 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if005 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if006 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if007 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if008 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if009 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if010 SwEdition containers
Ibm ≫ Business Automation Workflow Version 21.0.3 Update if011 SwEdition containers
Ibm ≫ Business Automation Workflow Version 22.0.1 SwEdition traditional
Ibm ≫ Business Automation Workflow Version 22.0.1 Update - SwEdition containers
Ibm ≫ Business Automation Workflow Version 22.0.1 Update if001 SwEdition containers
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
https://www.ibm.com/support/pages/node/6829847