First published: Fri Dec 09 2022(Updated: )
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 241583.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect Enterprise | <=4.1 | |
IBM App Connect Enterprise | <=4.2 | |
IBM App Connect Enterprise | <=5.0-lts | |
IBM App Connect Enterprise | <=5.1 | |
IBM App Connect Enterprise | <=5.2 | |
IBM App Connect Enterprise | <=6.0 | |
IBM App Connect Enterprise | <=6.1 | |
IBM App Connect Enterprise | <=6.2 | |
IBM App Connect Enterprise | =4.1 | |
IBM App Connect Enterprise | =4.2 | |
IBM App Connect Enterprise | =5.0 | |
IBM App Connect Enterprise | =5.1 | |
IBM App Connect Enterprise | =5.2 | |
IBM App Connect Enterprise | =6.0 | |
IBM App Connect Enterprise | =6.1 | |
IBM App Connect Enterprise | =6.2 | |
Red Hat OpenShift | ||
All of | ||
Any of | ||
IBM App Connect Enterprise | =4.1 | |
IBM App Connect Enterprise | =4.2 | |
IBM App Connect Enterprise | =5.0 | |
IBM App Connect Enterprise | =5.1 | |
IBM App Connect Enterprise | =5.2 | |
IBM App Connect Enterprise | =6.0 | |
IBM App Connect Enterprise | =6.1 | |
IBM App Connect Enterprise | =6.2 | |
Red Hat OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43922 is a vulnerability in IBM App Connect Enterprise Certified Container that could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration.
The severity of CVE-2022-43922 is medium with a severity value of 6.5.
IBM App Connect Enterprise Certified Container versions 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 are affected by CVE-2022-43922.
To fix CVE-2022-43922, it is recommended to update IBM App Connect Enterprise Certified Container to a version that has a fix for the vulnerability.
More information about CVE-2022-43922 can be found at the IBM X-Force ID: 241583.