First published: Tue Jan 24 2023(Updated: )
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233975.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Workload Scheduler | =9.4 | |
IBM Tivoli Workload Scheduler | =9.5 | |
IBM Tivoli Workload Scheduler | =10.1 | |
IBM Workload Scheduler | <=9.4 | |
IBM Workload Scheduler | <=9.5 | |
IBM Workload Scheduler | <=10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38389 is a vulnerability in IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 that allows for XML External Entity Injection (XXE) attacks.
CVE-2022-38389 allows remote attackers to exploit the vulnerability and potentially expose sensitive information or consume memory resources.
CVE-2022-38389 has a severity of 9.1 (Critical).
IBM Tivoli Workload Scheduler versions 9.4, 9.5, and 10.1 are affected by CVE-2022-38389.
To fix CVE-2022-38389, IBM recommends applying the necessary fixes or updates provided in their official documentation.