CVE-2022-38389: IBM Tivoli Workload Scheduler XML external entity injection
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233975.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38389?
CVE-2022-38389 is a vulnerability in IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 that allows for XML External Entity Injection (XXE) attacks.
How does CVE-2022-38389 impact IBM Tivoli Workload Scheduler?
CVE-2022-38389 allows remote attackers to exploit the vulnerability and potentially expose sensitive information or consume memory resources.
What is the severity of CVE-2022-38389?
CVE-2022-38389 has a severity of 9.1 (Critical).
Which versions of IBM Tivoli Workload Scheduler are affected by CVE-2022-38389?
IBM Tivoli Workload Scheduler versions 9.4, 9.5, and 10.1 are affected by CVE-2022-38389.
How can CVE-2022-38389 be fixed?
To fix CVE-2022-38389, IBM recommends applying the necessary fixes or updates provided in their official documentation.