CVE-2022-22463: SQL Injection
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.
Other sources
IBM Security Access Manager Appliance is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22463?
CVE-2022-22463 is a vulnerability in IBM Security Access Manager Appliance that allows remote attackers to perform SQL injection.
How does CVE-2022-22463 impact IBM Security Access Manager Appliance?
CVE-2022-22463 allows remote attackers to send specially crafted SQL statements to view, add, modify, or delete information in the back-end database of IBM Security Access Manager Appliance.
What is the severity level of CVE-2022-22463?
CVE-2022-22463 has a severity level of 6.5, which is considered medium.
What software versions are affected by CVE-2022-22463?
IBM Security Access Manager Appliance versions 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 are affected by CVE-2022-22463.
Is there a fix available for CVE-2022-22463?
Yes, IBM has provided a fix for CVE-2022-22463. Please refer to the official IBM support page for more details.