Vulnerability Description
The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this issue by reducing the amount of time the sensitive data is visible in memory. IBM X-Force ID: 241675.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 Mirror For I | 7.4 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/241675VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6981113PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/241675VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6981113PatchVendor Advisory
FAQ
What is CVE-2022-43928?
CVE-2022-43928 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their co...
How severe is CVE-2022-43928?
CVE-2022-43928 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43928?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2 Mirror For I.