CVE-2022-41296: IBM Db2U cross-site respect forgery
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
Other sources
IBM Db2U is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41296?
CVE-2022-41296 is a vulnerability in IBM Db2U that allows for cross-site request forgery, enabling an attacker to execute unauthorized actions.
Which versions of IBM Db2U are affected by CVE-2022-41296?
IBM Db2U versions 3.5, 4.0, and 4.5 are affected by CVE-2022-41296.
What is the severity of CVE-2022-41296?
CVE-2022-41296 has a severity rating of 8.8 (high).
How does CVE-2022-41296 impact security?
CVE-2022-41296 can lead to cross-site request forgery attacks, allowing an attacker to execute malicious actions through a trusted user's browser.
Are there any references for CVE-2022-41296?
Yes, you can find more information about CVE-2022-41296 at the following references: [1](https://exchange.xforce.ibmcloud.com/vulnerabilities/237210) and [2](https://www.ibm.com/support/pages/node/6843071).