CVE-2023-35022: IBM InfoSphere Information Server improper authentication
IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.
Other sources
IBM InfoSphere Information Server could allow a local user to update projects that they do not have the authorization to access.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35022?
CVE-2023-35022 is considered a high severity vulnerability as it allows unauthorized local users to update projects.
How do I fix CVE-2023-35022?
To fix CVE-2023-35022, download and apply the latest patches provided by IBM for InfoSphere Information Server version 11.7.
Who is affected by CVE-2023-35022?
CVE-2023-35022 affects local users of IBM InfoSphere Information Server version 11.7 who may exploit the flaw to gain unauthorized access.
What impact does CVE-2023-35022 have on IBM InfoSphere Information Server?
CVE-2023-35022 allows unauthorized local users to alter projects they should not have access to, potentially compromising data integrity.
Is CVE-2023-35022 a local or remote vulnerability?
CVE-2023-35022 is classified as a local vulnerability, meaning it can only be exploited by individuals who already have local access to the system.