SB20220720107 - Denial of service in IBM UrbanCode Build



SB20220720107 - Denial of service in IBM UrbanCode Build

Published: July 20, 2022 Updated: October 25, 2024

Security Bulletin ID SB20220720107
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Data Handling (CVE-ID: CVE-2022-29885)

CWE-ID: CWE-19 - Data Handling

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Clear


The vulnerability allows a remote attacker to perform DoS attack.

The vulnerability exists due to an error in documentation for the EncryptInterceptor, which incorrectly stated that it enabled Tomcat clustering to run over an untrusted network. A remote attacker can perform a denial of service attack against the exposed EncryptInterceptor.


Remediation

Install update from vendor's website.