First published: Fri Sep 16 2022(Updated: )
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Transformation Advisor | <=2.0.1 - 3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40154 is a vulnerability in the XStream package that allows a remote authenticated attacker to cause a denial of service by exploiting a stack-based buffer overflow.
CVE-2022-40154 has a severity rating of high.
IBM Disconnected Log Collector versions v1.0 to v1.8.2 are affected by CVE-2022-40154 and can be exploited to cause a denial of service condition.
A fix for CVE-2022-40154 may be available from the vendor. It is recommended to check with IBM for any available patches or updates.
More information about CVE-2022-40154 can be found in the references provided: CVE-2022-40154 on Chromium Bug Tracker, XStream GitHub issue #304, and Red Hat Bugzilla #2128960.