OS Command Injection in IBM InfoSphere Information Server and IBM InfoSphere Information Server for Cloud - CVE-2022-22454
Published: May 10, 2022
Vulnerability identifier: #VU62902
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22454
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation. A local user can execute arbitrary commands on the system with elevated privileges.
Affected software
IBM InfoSphere Information Server
IBM InfoSphere Information Server for Cloud
IBM InfoSphere Information Server for Cloud
How to mitigate CVE-2022-22454
Install updates from vendor's website.
IBM InfoSphere Information Server - update to 11.7.1.3 Service pack 4
IBM InfoSphere Information Server for Cloud - update to 11.7.1.3 Service pack 4
IBM InfoSphere Information Server for Cloud - update to 11.7.1.3 Service pack 4