Information disclosure in Open Enclave SDK - CVE-2022-21233

 

Information disclosure in Open Enclave SDK - CVE-2022-21233

Published: August 16, 2022 / Updated: August 25, 2022


Vulnerability identifier: #VU66522
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21233
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to improper isolation of shared resources. A local administrator can gain unauthorized access to sensitive information on the system.


Affected software

Open Enclave SDK
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
HPE Synergy 480 Gen10 Plus Compute Module
Amazon Linux AMI
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
EMC Integrated Data Protection Appliance
Dell EMC NetWorker vProxy
SIMATIC S7-1500 TM MFP - BIOS
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE Edgeline e920 Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920t Server Blade
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL220n Gen10 Plus Server
Intel Processor Microcode Package for Linux
microcode_ctl
intel-microcode (Ubuntu package)
ucode-intel-debugsource
ucode-intel-debuginfo
ucode-intel

How to mitigate CVE-2022-21233

Install updates from vendor's website.

Open Enclave SDK - update to 0.18.2
HPE ProLiant DL20 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant ML30 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022
microcode_ctl - update to 2.1-37
microcode_ctl - addressed in versions 2.1-47.4.fc35, 2.1-51.1.fc36
microcode_ctl - update to 2.1-53
intel-microcode (Ubuntu package) - addressed in versions 3.20220809.0ubuntu0.18.04.1, 3.20220809.0ubuntu0.20.04.1, 3.20220809.0ubuntu0.22.04.1
Dell EMC NetWorker vProxy - update to 4.3.0-36
Intel Processor Microcode Package for Linux - update to 20220809
ucode-intel-debugsource - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel-debuginfo - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel - addressed in versions 20220809-3.46.1, 20220809-13.101.1, 20220809-150000.3.78.1, 20220809-150100.3.214.1, 20220809-150200.18.1

External References

Related Security Bulletins