CVE-2022-22454: OS Command Injection
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Other sources
IBM InfoSphere Information Server could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22454?
CVE-2022-22454 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows a locally authenticated attacker to execute arbitrary commands on the system.
How severe is CVE-2022-22454?
CVE-2022-22454 has a severity value of 7.8, which is considered high.
Which software versions are affected by CVE-2022-22454?
IBM InfoSphere Information Server version 11.7 is affected by CVE-2022-22454.
Is IBM AIX affected by CVE-2022-22454?
No, IBM AIX is not affected by CVE-2022-22454.
Is there a patch available for CVE-2022-22454?
Yes, a patch is available for CVE-2022-22454. You can find it at the following URL: https://www.ibm.com/support/pages/node/878310