Heap-based buffer overflow in Zlib - CVE-2022-37434
Published: August 7, 2022 / Updated: October 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing a large gzip header within inflateGetHeader in inflate.c. A remote attacker can pass a specially crafted file to the affected application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
cflinuxfs3
Telemetry Dashboard
IBM Security Verify Gateway for Radius
IBM Security Verify Gateway for Windows Login
IBM Security Verify Bridge for Directory Sync
Oracle Enterprise Communications Broker
Storage Fusion Data Foundation
Oracle Communications Operations Monitor
Oracle Agile Engineering Data Management
Oracle Business Intelligence Enterprise Edition
Liquidware
Db2 Big SQL
IBM OpenPages with Watson
IBM supplied MQ Advanced container images
dashDB Local
Oracle Communications Policy Management
Citrix Workspace App
Webex App VDI
ObjectScale
SINEC PNI
IBM Planning Analytics Workspace
PowerStore T
IBM Cloud Pak for Watson AIOps
EMC ECS
XtremIO X2
Storage Protect Server
IBM Engineering Systems Design Rhapsody
Robotic Process Automation for Cloud Pak
Gentoo Linux
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux Enterprise Storage
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
Oracle Solaris
FreeBSD
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
iPadOS
Apple iOS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
watchOS
Lumada APM
OpenJ9
Red Hat OpenShift Serverless
Harbor
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Service Binding Operator
Data Lakehouse
Migration Toolkit for Runtimes
IBM Operations Analytics Predictive Insights
Service Telemetry Framework
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Migration Toolkit for Virtualization
Ansible Automation Platform
IBM Security Guardium Key Lifecycle Manager (GKLM)
Dell Secure Connect Gateway
IBM Intelligent Operations Center
OpenShift Logging
Tenable Nessus
WebSphere Remote Server
Oracle Communications Diameter Signaling Router
Oracle Communications Session Router
Oracle Communications Subscriber-Aware Load Balancer
Oracle Enterprise Session Router
IBM Security Verify Governance
Hyperion Financial Management
Oracle HTTP Server
Oracle Communications Cloud Native Core Binding Support Function
Autodesk Infraworks
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
Session Smart Router
IBM Cloud Application Performance Management (APM)
IBM QRadar WinCollect Agent
NetWorker
IBM Observability with Instana
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
JD Edwards EnterpriseOne Tools
IBM DataPower Gateway
VMware Horizon Client
VLC Media Player
RecoverPoint for VMs
MySQL Server
Oracle TimesTen In-Memory Database
IBM DB2
LANTIME Operating System Firmware (LTOS)
SIMATIC MV560 X
SIMATIC MV540 H
SIMATIC MV540 S
SIMATIC MV550 H
SIMATIC MV550 S
SIMATIC MV560 U
PowerScale OneFS
MySQL Workbench
Splunk Universal Forwarder
Oracle Outside In Technology
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
klibc-utils (Ubuntu package)
libklibc (Ubuntu package)
zlib-static
zlib-devel
zlib
minizip
minizip-devel
zlib (Red Hat package)
zlib-bin (Ubuntu package)
libz1-debuginfo
libz1-debuginfo-32bit
zlib-debugsource
libz1-32bit
libz1
zlib1g (Ubuntu package)
lib32z1 (Ubuntu package)
libx32z1 (Ubuntu package)
lib64z1 (Ubuntu package)
zlib (Debian package)
zlib-devel-static
zlib-devel-32bit
zlib-devel-static-32bit
zlib-help
zlib-debuginfo
libminizip1
libminizip1-32bit
libminizip1-32bit-debuginfo
libz1-32bit-debuginfo
libminizip1-debuginfo
sys-libs/zlib
sudo-help
sudo-debugsource
sudo-devel
sudo-debuginfo
sudo
mariadb-connector-c-debugsource
mariadb-connector-c
mariadb-connector-c-debuginfo
mariadb-connector-c-devel
rsync
rsync (Ubuntu package)
rsync-debugsource
rsync-help
rsync-debuginfo
rsync (Red Hat package)
deltarpm
deltarpm-debuginfo
drpmsync
deltarpm-debugsource
python2-deltarpm
python3-deltarpm
deltarpm-help
mysql
Oracle Communications Core Session Manager
PeopleSoft Enterprise PeopleTools
Oracle AutoVue
Oracle Communications Session Border Controller
IBM Security Guardium
Cisco Jabber
Oracle Retail Advanced Inventory Planning
Oracle Retail Predictive Application Server
Oracle Hospitality Simphony
Siebel CRM Deployment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Cisco Webex Meetings
Voice Gateway
IBM Cloud Pak System
Dell EMC NetWorker vProxy
IBM FileNet Content Manager
Dell EMC VxRail Appliance
IBM QRadar Network Packet Capture
How to mitigate CVE-2022-37434
Lumada APM - update to 6.4.0.1
OpenJ9 - update to 0.35.0
cflinuxfs3 - addressed in versions 0.316.0, 0.317.0
Service Binding Operator - update to 1.3.1
Data Lakehouse - update to 1.1.0.0
Migration Toolkit for Runtimes - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.26.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift API for Data Protection (OADP) - update to 1.1.1
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - update to 1.7.6
Harbor - update to 1.10.13
OpenShift Service Mesh - update to 2.3.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.8, 2.6.2, 2.6.3
Migration Toolkit for Virtualization - update to 2.4.3
VLC Media Player - update to 3.0.19
Storage Fusion Data Foundation - update to 4.13
Red Hat OpenShift Container Platform - addressed in versions 4.11.12, 4.11.45
Dell Secure Connect Gateway - update to 5.14.00.10
OpenShift Logging - addressed in versions 5.3.13, 5.3.14, 5.4.8, 5.5.4, 5.5.5
MySQL Server - update to 8.0.32
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.034, 7.06.007
Db2 Big SQL - update to 7.6.2
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
MySQL Workbench - update to 8.0.32
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
JD Edwards EnterpriseOne Tools - update to 9.2.8.0
IBM supplied MQ Advanced container images - update to 9.3.0.1-r3
IBM DataPower Gateway - addressed in versions 10.5.0.17, 10.6.0.5, 10.6.4.0
macOS - addressed in versions 11.7.1 20G918, 12.6.1 21G217, 13.0 22A380
Oracle TimesTen In-Memory Database - update to 11.2.2.8.65
dashDB Local - update to 11.5.9.0
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
iPadOS - addressed in versions 15.7.1 19H117, 16.1 20B82
Apple iOS - addressed in versions 15.7.1 19H117, 16.1 20B82
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
klibc-utils (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.7-1ubuntu5.2, 2.0.10-4ubuntu0.1, 2.0.13-1ubuntu0.1, 2.0.13-4ubuntu0.1
libklibc (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.7-1ubuntu5.2, 2.0.10-4ubuntu0.1, 2.0.13-1ubuntu0.1, 2.0.13-4ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.1, 1.0.8.2, 1.0.8.5
zlib-static - update to 1.2.7-21
zlib-devel - addressed in versions 1.2.7-21, 1.2.11-19.0.1
zlib - addressed in versions 1.2.7-21, 1.2.11-19.0.1
minizip - update to 1.2.7-21
minizip-devel - update to 1.2.7-21
zlib (Red Hat package) - addressed in versions 1.2.7-21.el7_9, 1.2.11-19.el8_6, 1.2.11-32.el9_0
zlib-bin (Ubuntu package) - update to 1.2.8.dfsg-1ubuntu1
zlib - update to 1.2.8-7.20
libz1-debuginfo - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
libz1-debuginfo-32bit - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1
zlib-debugsource - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
libz1-32bit - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
libz1 - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
zlib-devel - addressed in versions 1.2.8-12.9.1, 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
zlib1g (Ubuntu package) - addressed in versions 1:1.2.11.dfsg-2ubuntu1.5, 1:1.2.11.dfsg-0ubuntu2.2, 1:1.2.11.dfsg-2ubuntu9.2
lib32z1 (Ubuntu package) - addressed in versions 1:1.2.11.dfsg-2ubuntu1.5, 1:1.2.11.dfsg-0ubuntu2.2, 1:1.2.11.dfsg-2ubuntu9.2
libx32z1 (Ubuntu package) - addressed in versions 1:1.2.11.dfsg-2ubuntu1.5, 1:1.2.11.dfsg-0ubuntu2.2, 1:1.2.11.dfsg-2ubuntu9.2
lib64z1 (Ubuntu package) - addressed in versions 1:1.2.11.dfsg-2ubuntu1.5, 1:1.2.11.dfsg-0ubuntu2.2, 1:1.2.11.dfsg-2ubuntu9.2
zlib (Debian package) - update to 1:1.2.11.dfsg-2+deb11u2
zlib-devel-static - addressed in versions 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
zlib-devel-32bit - addressed in versions 1.2.11-3.9.1, 1.2.11-11.22.1, 1.2.11-150000.3.33.1
zlib-devel-static-32bit - addressed in versions 1.2.11-3.9.1, 1.2.11-150000.3.33.1
zlib-debugsource - update to 1.2.11-20
zlib - update to 1.2.11-20
zlib-help - update to 1.2.11-20
minizip - update to 1.2.11-20
zlib-devel - update to 1.2.11-20
minizip-devel - update to 1.2.11-20
zlib-debuginfo - update to 1.2.11-20
zlib - addressed in versions 1.2.11-32.fc35, 1.2.11-33.fc36, 1.2.12-5.fc37
libminizip1 - update to 1.2.11-150000.3.33.1
minizip-devel - update to 1.2.11-150000.3.33.1
libminizip1-32bit - update to 1.2.11-150000.3.33.1
libminizip1-32bit-debuginfo - update to 1.2.11-150000.3.33.1
libz1-32bit-debuginfo - update to 1.2.11-150000.3.33.1
libminizip1-debuginfo - update to 1.2.11-150000.3.33.1
sys-libs/zlib - update to 1.2.12-r3
zlib - update to 1.2.13
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
sudo-help - update to 1.9.2-6
sudo-debugsource - update to 1.9.2-6
sudo-devel - update to 1.9.2-6
sudo-debuginfo - update to 1.9.2-6
sudo - update to 1.9.2-6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
SINEC PNI - update to 2.0
IBM Planning Analytics Workspace - update to 2.0.87
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
mariadb-connector-c-debugsource - update to 3.0.6-8
mariadb-connector-c - update to 3.0.6-8
mariadb-connector-c-debuginfo - update to 3.0.6-8
mariadb-connector-c-devel - update to 3.0.6-8
rsync - update to 3.0.6-12.14
rsync (Ubuntu package) - addressed in versions 3.1.2-2.1ubuntu1.5, 3.1.3-8ubuntu0.4
rsync-debugsource - update to 3.1.3-8
rsync-help - update to 3.1.3-8
rsync-debuginfo - update to 3.1.3-8
rsync - update to 3.1.3-8
rsync (Red Hat package) - addressed in versions 3.1.3-14.el8_6.5, 3.1.3-19.el8, 3.2.3-18.el9
rsync - addressed in versions 3.2.5-1.fc35, 3.2.5-1.fc36
SIMATIC MV560 X - update to 3.3.4
SIMATIC MV540 H - update to 3.3.4
SIMATIC MV540 S - update to 3.3.4
SIMATIC MV550 H - update to 3.3.4
SIMATIC MV550 S - update to 3.3.4
SIMATIC MV560 U - update to 3.3.4
IBM Cloud Transformation Advisor - update to 3.4.0
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Pak for Watson AIOps - update to 3.6.1
deltarpm - update to 3.6.2-5
deltarpm-debuginfo - update to 3.6.2-5
drpmsync - update to 3.6.2-5
deltarpm-debugsource - update to 3.6.2-5
python2-deltarpm - update to 3.6.2-5
python3-deltarpm - update to 3.6.2-5
deltarpm-help - update to 3.6.2-5
EMC ECS - update to 3.8.0.2
Dell EMC NetWorker vProxy - update to 4.3.0-36
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.1-11
Dell EMC VxRail Appliance - addressed in versions 7.0.401, 8.0.000
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 6
mysql - update to 8.0.28-2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
watchOS - update to 9.1 20S75
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10, 9.5.0.6
IBM QRadar WinCollect Agent - update to 10.1.1
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7, 11.5, 11.5.9
NetWorker - update to 19.9.0.1
Robotic Process Automation for Cloud Pak - update to 21.0.7
IBM Observability with Instana - update to 281
Links to Public Exploits and PoC-codes
External References
- https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764
- https://github.com/ivd38/zlib_overflow
- https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
- https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
- http://www.openwall.com/lists/oss-security/2022/08/05/2
Related Security Bulletins
- Remote code execution in zlib
- Ubuntu update for zlib
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- Heap-based buffer overflow in cflinuxfs3
- Ubuntu update for rsync
- Cloud Foundry Foundation cflinuxfs3 update for zlib
- Debian update for zlib
- Heap-based buffer overflow in Harbor
- FreeBSD update for zlib
- SUSE update for zlib
- Slackware Linux update for zlib
- Ubuntu update for zlib
- Oracle Solaris update for third-party software
- Red Hat Enterprise Linux 8 update for zlib
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in openj9
- Gentoo update for zlib
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Red Hat Enterprise Linux 9 update for zlib
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Red Hat Enterprise Linux 8 update for rsync
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Service Binding Operator
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Red Hat Enterprise Linux 9 update for rsync
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Multiple vulnerabilities in Dell NetWorker vProxy
- Amazon Linux AMI update for zlib
- Heap-based buffer overflow in IBM Security Verify for Gateway (RADIUS & WinLogin) and for Bridge (DirSync)
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in OpenShift Serverles
- Multiple vulnerabilities in IBM QRadar Wincollect agent
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Dell PowerScale OneFS
- Heap-based buffer overflow in Hitachi Energy Lumada Asset Performance Management
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Heap-based buffer overflow in Oracle TimesTen In-Memory Database
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Red Hat Enterprise Linux 7 update for zlib
- CentOS 7 update for zlib
- Heap-based buffer overflow in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Heap-based buffer overflow in Oracle Enterprise Session Router
- Heap-based buffer overflow in Oracle Enterprise Communications Broker
- Heap-based buffer overflow in Oracle Communications Subscriber-Aware Load Balancer
- Heap-based buffer overflow in Oracle Communications Session Router
- Heap-based buffer overflow in Oracle Communications Core Session Manager
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- Multiple vulnerabilities in Oracle Communications Policy Management
- Heap-based buffer overflow in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in Oracle Retail Predictive Application Server
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Dell ECS
- Splunk Universal Forwarder update for third-party packages
- Heap-based buffer overflow in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in IBM FileNet Content Manager
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Siemens SIMATIC MV500 Devices
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle AutoVue
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Heap-based buffer overflow in Oracle Retail Advanced Inventory Planning
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in Dell NetWorker
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- VLC Media Player update for third-party components
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Siemens SINEC PNI
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Red Hat Enterprise Linux 8.6 Extended Update Support update for rsync
- Heap-based buffer overflow in Hyperion Financial Management
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- openEuler update for zlib
- openEuler update for rsync
- openEuler update for sudo
- openEuler update for deltarpm
- openEuler update for mariadb-connector-c
- openEuler update for mysql
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Ubuntu update for klibc
- Ubuntu update for klibc
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Siebel CRM Deployment
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Amazon Linux AMI update for rsync
- Amazon Linux AMI update for zlib
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Fedora 35 update for rsync
- Fedora 36 update for rsync
- Fedora 37 update for zlib
- Fedora 35 update for zlib
- Fedora 36 update for zlib
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in IBM dashDB Local
- Anolis OS update for zlib
- Anolis OS update for zlib
- Multiple vulnerabilities in IBM Storage Fusion Data Foundation
- Meinberg LANTIME firmware update for third-party components (October 2022)
- Multiple vulnerabilities in IBM DataPower Gateway
- Heap-based buffer overflow in Oracle Hospitality Simphony
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data