CVE-2022-40752: Command Injection
Published Nov 2, 2022
·Updated
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
Affected Software
11 affected componentsFixes available
IBM InfoSphere Information Server, InfoSphere Information Server on Cloud<=11.7
IBM InfoSphere Information Server=11.7
IBM Infosphere Information Server On Cloud=11.7
IBM AIX
Linux Linux kernel
Microsoft Windows
All of the following
Any of the following
IBM InfoSphere Information Server=11.7
IBM Infosphere Information Server On Cloud=11.7
Any of the following
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Nov 2, 2022
CVE Published
via IBM·12:00 AM
Nov 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-40752.
2
What is the severity of CVE-2022-40752?
The severity of CVE-2022-40752 is critical.
3
Which versions of IBM InfoSphere DataStage are affected by this vulnerability?
IBM InfoSphere DataStage 11.7 is affected by this vulnerability.
4
What is the impact of this vulnerability?
This vulnerability allows for command injection, which can lead to arbitrary code execution.
5
How can I fix CVE-2022-40752?
To fix CVE-2022-40752, apply the patch provided by IBM at https://www.ibm.com/support/pages/node/878310.