Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 7 |
CVE-ID | CVE-2022-32212 CVE-2022-32223 CVE-2022-22393 CVE-2022-32215 CVE-2022-32213 CVE-2022-22475 CVE-2022-32214 |
CWE-ID | CWE-703 CWE-427 CWE-200 CWE-444 CWE-287 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #2 is available. |
Vulnerable software Subscribe |
IBM Cloud Transformation Advisor Server applications / Other server solutions |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 7 vulnerabilities.
EUVDB-ID: #VU65273
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-32212
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to IsIPAddress does not properly checks if an IP address is invalid or not. A remote unauthenticated attacker can exploit this vulnerability to bypass the IsAllowedHost check and execute arbitrary code on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU65276
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-32223
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local attacker to elevate privileges on the system
The vulnerability exists due to DLL search order hijacking of providers.dll. A local attacker can place a specially crafted .dll file and elevate privileges on the system
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU65906
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-22393
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU65282
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-32215
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to llhttp parser in the http module does not correctly handle multi-line Transfer-Encoding headers. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU65275
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-32213
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially-crafted request to lead to HTTP Request Smuggling to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU64197
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-22475
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to an unspecified error. A remote authenticated user can spoof identity of other application users.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU65278
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-32214
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to llhttp parser in the http module does not strictly use the CRLF sequence to delimit HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Cloud Transformation Advisor: before 3.2.2
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6616293
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?