CVE-2022-38714: IBM DataStage on Cloud Pak for Data information disclosure
IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.
Other sources
IBM DataStage on Cloud Pak for Data stores sensitive credential information that can be read by a privileged user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38714?
CVE-2022-38714 has been classified with a high severity level due to its potential to expose sensitive credential information.
How do I fix CVE-2022-38714?
To mitigate CVE-2022-38714, ensure that access controls are properly configured to restrict privileged user access to sensitive credential information.
What versions of IBM DataStage are affected by CVE-2022-38714?
CVE-2022-38714 affects IBM DataStage on Cloud Pak for Data versions 4.0.6 to 4.5.2.
What types of information can be exposed by CVE-2022-38714?
CVE-2022-38714 can expose sensitive credential information stored within IBM DataStage to privileged users.
Is there a patch available for CVE-2022-38714?
As of now, specific patch details for CVE-2022-38714 have not been publicly disclosed, so it's advised to check IBM's support channels for updates.