CVE-2022-22317: Critical severity ibm curam social program management vulnerability
Published Jun 20, 2022
·Updated
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
Affected Software
8 affected components
IBM Curam Social Program Management=8.0.0
IBM Curam Social Program Management=8.0.1
HP HP-UX
IBM AIX
IBM Z\/os
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jun 20, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22317?
The severity of CVE-2022-22317 is critical, with a severity value of 9.8.
2
Which versions of IBM Curam Social Program Management are affected by CVE-2022-22317?
IBM Curam Social Program Management versions 8.0.0 and 8.0.1 are affected by CVE-2022-22317.
3
How does CVE-2022-22317 impact IBM Curam Social Program Management?
CVE-2022-22317 allows an authenticated user to impersonate another user on the system by not invalidating the session after logout.
4
Is HP-UX vulnerable to CVE-2022-22317?
No, HP-UX is not vulnerable to CVE-2022-22317.
5
Where can I find more information about CVE-2022-22317?
More information about CVE-2022-22317 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/218281), [Link 2](https://www.ibm.com/support/pages/node/6596049)