Vulnerability Description
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling External Authentication Server | 3.4.3.2 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/220144VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6558928PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/220144VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6558928PatchVendor Advisory
FAQ
What is CVE-2022-22349?
CVE-2022-22349 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import i...
How severe is CVE-2022-22349?
CVE-2022-22349 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22349?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling External Authentication Server.