Improper Handling of Parameters in amazon.aws - CVE-2022-3697

 

Improper Handling of Parameters in amazon.aws - CVE-2022-3697

Published: July 21, 2023


Vulnerability identifier: #VU78492
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3697
CWE-ID: CWE-233
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.


Affected software

amazon.aws
IBM Watson Machine Learning Accelerator
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
Ubuntu
openEuler
ansible (Ubuntu package)
ansible
ansible-doc
ansible-test

How to mitigate CVE-2022-3697

Install updates from vendor's website.

amazon.aws - update to 5.1.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
ansible (Ubuntu package) - update to Ubuntu Pro
ansible - update to 2.9.27-7
ansible-doc - update to 2.9.27-7
ansible-test - update to 2.9.27-7
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Match 360 - update to 4.7.0

External References

Related Security Bulletins