CVE-2022-22425: Critical severity sap information steward vulnerability
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Other sources
IBM InfoSphere Information Server is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22425.
What is the severity of CVE-2022-22425?
The severity of CVE-2022-22425 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2022-22425?
IBM InfoSphere Information Server 11.7 is affected by CVE-2022-22425.
How can a remote attacker exploit CVE-2022-22425?
A remote attacker could execute arbitrary commands on the system by exploiting the CSV Injection vulnerability.
Is there a patch available for CVE-2022-22425?
Yes, IBM has released a patch for CVE-2022-22425. You can find more information and download the patch from IBM's support page: <a href="https://www.ibm.com/support/pages/node/878310">https://www.ibm.com/support/pages/node/878310</a>