Information disclosure in follow-redirects - CVE-2022-0536

 

Information disclosure in follow-redirects - CVE-2022-0536

Published: March 28, 2022


Vulnerability identifier: #VU61668
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0536
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

follow-redirects
App Connect Enterprise Certified Container
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Automation Manager
Netcool Operations Insight
Red Hat Integration - Service Registry
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
IBM Cloud Pak System
IBM Watson Machine Learning Accelerator
IBM MQ Appliance
IBM i Modernization Engine for Lifecycle Integration
QRadar Assistant
Robotic Process Automation for Cloud Pak
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cognos Controller
Cloud Pak for Security (CP4S)
Ubuntu
node-follow-redirects (Ubuntu package)
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2022-0536

Install updates from vendor's website.

follow-redirects - update to 1.14.8
App Connect Enterprise Certified Container - addressed in versions 1.1.8, 4.0.0
Migration Toolkit for Containers - update to 1.7.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.3.10, 2.3.11, 2.4.3, 2.4.4
IBM Cloud Pak System - update to 2.3.3.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.11.0, 4.17.5
IBM MQ Appliance - addressed in versions 9.2.0.6, 9.2.5
IBM Cognos Controller - update to 11.0.1.0.3
node-follow-redirects (Ubuntu package) - addressed in versions 1.2.4-1ubuntu0.18.04.1~esm1, 1.2.4-1ubuntu0.20.04.1~esm1, 1.14.9+~1.14.1-1ubuntu0.1~esm1
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.14.0
Red Hat Integration - Service Registry - update to 2.3.0
IBM Cloud Pak for Multicloud Management - update to 2.3.5
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
IBM Security QRadar Analyst Workflow - update to 2.31.4
QRadar Assistant - update to 3.6.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1

External References

Related Security Bulletins