Multiple vulnerabilities in IBM Tivoli Netcool Impact



Published: 2022-09-26
Risk High
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2022-26520
CVE-2022-21724
CWE-ID CWE-20
CWE-665
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
IBM Tivoli Netcool Impact
Server applications / Other server solutions

Vendor IBM Corporation

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Input validation error

EUVDB-ID: #VU62716

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-26520

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to create arbitrary files on the system.

The vulnerability exists due to insufficient validation of user-supplied input when handling jdbc URL or its properties. A remote attacker can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties.

Successful exploitation of the vulnerability may allow an attacker to create and executable arbitraru JSP file under a Tomcat web root.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Tivoli Netcool Impact: 7.1.0 - 7.1.0.24

External links

http://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-postgresql-shipped-with-ibm-tivoli-netcool-impact-cve-2022-26520-cve-2022-21724-220313/
http://www.ibm.com/support/pages/node/6602599


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Improper initialization

EUVDB-ID: #VU62714

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-21724

CWE-ID: CWE-665 - Improper Initialization

Exploit availability: No

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to improper initialization in pgjdbc driver when handling attacker-controlled URL in connection properties as the driver does not verify if the class implements the expected interface before instantiating the class. A remote attacker can pass specially crafted URL to the affected application and execute arbitrary code in the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Tivoli Netcool Impact: 7.1.0 - 7.1.0.24

External links

http://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-postgresql-shipped-with-ibm-tivoli-netcool-impact-cve-2022-26520-cve-2022-21724-220313/
http://www.ibm.com/support/pages/node/6602599


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###