First published: Fri Sep 16 2022(Updated: )
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Transformation Advisor | <=2.0.1 - 3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40155 is a vulnerability in the XStream package that allows an attacker to cause a denial of service by triggering a stack-based buffer overflow.
CVE-2022-40155 affects IBM Disconnected Log Collector versions v1.0 to v1.8.2, allowing a remote authenticated attacker to crash the parser and cause a denial of service.
CVE-2022-40155 has a severity rating of high.
An attacker can exploit CVE-2022-40155 by sending a specially-crafted XML data to trigger the stack-based buffer overflow and crash the parser.
The CWEs associated with CVE-2022-40155 are CWE-787 (Out-of-bounds Write) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).