IBM SDK, Java Technology Edition code execution
CVE-2022-40609

8.1HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 August 2023

Summary

The IBM SDK, Java Technology Edition versions 7.1.5.18 and 8.0.8.0 are vulnerable due to an unsafe deserialization flaw that could enable a remote attacker to execute arbitrary code on the affected system. By sending specifically crafted data to the application, the attacker can manipulate the deserialization process, potentially leading to unauthorized access and control over the system. Organizations using these versions should take immediate action to apply the necessary patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

SDK, Java Technology Edition 7.1.5.18, 8.0.8.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.