Information disclosure in Open Enclave SDK - CVE-2022-21233
Published: August 16, 2022 / Updated: August 25, 2022
Vulnerability identifier: #VU66522
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21233
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper isolation of shared resources. A local administrator can gain unauthorized access to sensitive information on the system.
Affected software
Open Enclave SDK
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
HPE Synergy 480 Gen10 Plus Compute Module
Amazon Linux AMI
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
EMC Integrated Data Protection Appliance
Dell EMC NetWorker vProxy
SIMATIC S7-1500 TM MFP - BIOS
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE Edgeline e920 Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920t Server Blade
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL220n Gen10 Plus Server
Intel Processor Microcode Package for Linux
microcode_ctl
intel-microcode (Ubuntu package)
ucode-intel-debugsource
ucode-intel-debuginfo
ucode-intel
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
HPE Synergy 480 Gen10 Plus Compute Module
Amazon Linux AMI
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
EMC Integrated Data Protection Appliance
Dell EMC NetWorker vProxy
SIMATIC S7-1500 TM MFP - BIOS
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE Edgeline e920 Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920t Server Blade
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL220n Gen10 Plus Server
Intel Processor Microcode Package for Linux
microcode_ctl
intel-microcode (Ubuntu package)
ucode-intel-debugsource
ucode-intel-debuginfo
ucode-intel
How to mitigate CVE-2022-21233
Install updates from vendor's website.
Open Enclave SDK - update to 0.18.2
HPE ProLiant DL20 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant ML30 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022
microcode_ctl - update to 2.1-37
microcode_ctl - addressed in versions 2.1-47.4.fc35, 2.1-51.1.fc36
microcode_ctl - update to 2.1-53
intel-microcode (Ubuntu package) - addressed in versions 3.20220809.0ubuntu0.18.04.1, 3.20220809.0ubuntu0.20.04.1, 3.20220809.0ubuntu0.22.04.1
Dell EMC NetWorker vProxy - update to 4.3.0-36
Intel Processor Microcode Package for Linux - update to 20220809
ucode-intel-debugsource - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel-debuginfo - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel - addressed in versions 20220809-3.46.1, 20220809-13.101.1, 20220809-150000.3.78.1, 20220809-150100.3.214.1, 20220809-150200.18.1
HPE ProLiant DL20 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant ML30 Gen10 Plus server - update to 1.60_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022
microcode_ctl - update to 2.1-37
microcode_ctl - addressed in versions 2.1-47.4.fc35, 2.1-51.1.fc36
microcode_ctl - update to 2.1-53
intel-microcode (Ubuntu package) - addressed in versions 3.20220809.0ubuntu0.18.04.1, 3.20220809.0ubuntu0.20.04.1, 3.20220809.0ubuntu0.22.04.1
Dell EMC NetWorker vProxy - update to 4.3.0-36
Intel Processor Microcode Package for Linux - update to 20220809
ucode-intel-debugsource - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel-debuginfo - addressed in versions 20220809-3.46.1, 20220809-13.101.1
ucode-intel - addressed in versions 20220809-3.46.1, 20220809-13.101.1, 20220809-150000.3.78.1, 20220809-150100.3.214.1, 20220809-150200.18.1
External References
Related Security Bulletins
- Information disclosure in Open Enclave SDK
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Information disclosure in Intel Processor Microcode Package for Linux
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Ubuntu update for intel-microcode
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Multiple vulnerabilities in Dell NetWorker vProxy
- Information disclosure in Certain HPE Apollo, XL Servers
- Information disclosure in Certain HPE Synergy Servers
- Information disclosure in Certain HPE Edgeline Servers
- Information disclosure in Certain HPE ProLiant DX Servers
- Information disclosure in Certain HPE ProLiant DL/ML Servers
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnetabilities in Dell EMC Integrated Data Protection Appliance
- openEuler update for microcode_ctl
- Amazon Linux AMI update for microcode_ctl
- Fedora 35 update for microcode_ctl
- Fedora 36 update for microcode_ctl
- Information disclosure in F5OS Intel BIOS