Improper Handling of Parameters in amazon.aws - CVE-2022-3697
Published: July 21, 2023
Vulnerability identifier: #VU78492
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3697
CWE-ID: CWE-233
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
amazon.aws
IBM Watson Machine Learning Accelerator
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
Ubuntu
openEuler
ansible (Ubuntu package)
ansible
ansible-doc
ansible-test
IBM Watson Machine Learning Accelerator
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Match 360
Ubuntu
openEuler
ansible (Ubuntu package)
ansible
ansible-doc
ansible-test
How to mitigate CVE-2022-3697
Install updates from vendor's website.
amazon.aws - update to 5.1.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
ansible (Ubuntu package) - update to Ubuntu Pro
ansible - update to 2.9.27-7
ansible-doc - update to 2.9.27-7
ansible-test - update to 2.9.27-7
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Match 360 - update to 4.7.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
ansible (Ubuntu package) - update to Ubuntu Pro
ansible - update to 2.9.27-7
ansible-doc - update to 2.9.27-7
ansible-test - update to 2.9.27-7
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Match 360 - update to 4.7.0
External References
Related Security Bulletins
- Multiple vulnerabilities in ICP Match 360
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Ubuntu update for ansible
- Ubuntu update for ansible
- Ubuntu update for ansible
- openEuler update for ansible