First published: Mon Oct 24 2022(Updated: )
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Ibm Infosphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22425.
The severity of CVE-2022-22425 is critical with a CVSS score of 9.8.
IBM InfoSphere Information Server 11.7 is affected by CVE-2022-22425.
A remote attacker could execute arbitrary commands on the system by exploiting the CSV Injection vulnerability.
Yes, IBM has released a patch for CVE-2022-22425. You can find more information and download the patch from IBM's support page: <a href="https://www.ibm.com/support/pages/node/878310">https://www.ibm.com/support/pages/node/878310</a>