First published: Wed Nov 30 2022(Updated: )
Helm could allow a remote authenticated attacker to obtain sensitive information, caused by repository credentials being passed to alternate domain. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 On Cloud Pak For Data | >=3.5<4.6 | |
Ibm Db2 Warehouse On Cloud Pak For Data | >=3.5<4.6 | |
IBM Db2U | =3.5 | |
IBM Db2U | =4.0 | |
IBM Db2U | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2022-41297.
The severity level of CVE-2022-41297 is medium.
The vulnerability affects IBM Db2U versions 3.5, 4.0, and 4.5.
This vulnerability can be exploited by sending a specially-crafted request to obtain sensitive information.
Yes, you can find more information about this vulnerability at the following references: [IBM X-Force Exchange - CVE-2022-41297](https://exchange.xforce.ibmcloud.com/vulnerabilities/237212), [IBM X-Force Exchange - CVE-2022-41297](https://exchange.xforce.ibmcloud.com/vulnerabilities/221551), [IBM Support - CVE-2022-41297](https://www.ibm.com/support/pages/node/6843071).