First published: Wed Mar 30 2022(Updated: )
IBM Watson Query could allow an authenticated user to obtain sensitive information that would allow them to examine or alter system configurations or data sources connected to the service.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Watson Query on Cloud Pak for Data | <=All instances on or after December 1, 2021 | |
IBM Watson Query | >=2021-12-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22410 is considered a critical vulnerability due to its potential to expose sensitive information and allow unauthorized access to system configurations.
To remediate CVE-2022-22410, it is recommended to upgrade to the latest version of IBM Watson Query with Cloud Pak for Data as a Service, which addresses this vulnerability.
CVE-2022-22410 affects all instances of IBM Watson Query with Cloud Pak for Data as a Service from December 1, 2021, onwards.
CVE-2022-22410 could allow an authenticated user to access sensitive information related to system configurations and connected data sources.
While there is no public indication of active exploitation of CVE-2022-22410, it is crucial to apply patches to mitigate risks.