CVE-2022-22353: Medium severity ibm big sql vulnerability
IBM Big SQL could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement.
Other sources
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22353.
What is the severity of CVE-2022-22353?
The severity of CVE-2022-22353 is medium with a severity value of 6.5.
What is the affected software for CVE-2022-22353?
The affected software for CVE-2022-22353 is IBM Big SQL on IBM Cloud Pak for Data versions 7.1.0, 7.1.1, 7.2.0, and 7.2.3.
How can an authenticated user exploit CVE-2022-22353?
An authenticated user with appropriate permissions can exploit CVE-2022-22353 by bypassing data masking rules using a CREATE TABLE SELECT statement.
How can I fix CVE-2022-22353?
To fix CVE-2022-22353, apply the relevant patches provided by IBM.