CVE-2022-38387: OS Command Injection
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.
Other sources
IBM Cloud Pak for Security (CP4S) could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38387?
The severity of CVE-2022-38387 is high with a score of 8.8.
How can a remote attacker exploit CVE-2022-38387?
A remote authenticated attacker can exploit CVE-2022-38387 by sending a specially crafted request to execute arbitrary commands on the system.
Which version of the affected software is vulnerable to CVE-2022-38387?
Versions 1.10.0.0 through 1.10.2.0 of IBM Cloud Pak for Security (CP4S) are vulnerable to CVE-2022-38387.
Is the Linux kernel vulnerable to CVE-2022-38387?
No, the Linux kernel is not vulnerable to CVE-2022-38387.
Where can I find more information about CVE-2022-38387?
You can find more information about CVE-2022-38387 at the IBM X-Force ID: 233786.