CVE-2022-22353
Summary
| CVE | CVE-2022-22353 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-14 17:15:00 UTC |
| Updated | 2022-03-22 14:40:00 UTC |
| Description | IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudera | Data Platform | 7.1.3 | All | All | All |
| Application | Cloudera | Data Platform | 7.1.4 | All | All | All |
| Application | Cloudera | Data Platform | 7.1.5 | All | All | All |
| Application | Cloudera | Data Platform | 7.1.7 | All | All | All |
| Application | Ibm | Big Sql | 7.1.0 | All | All | All |
| Application | Ibm | Big Sql | 7.1.1 | All | All | All |
| Application | Ibm | Big Sql | 7.2.3 | All | All | All |
| Application | Ibm | Big Sql | All | All | All | All |
| Application | Ibm | Cloud Pak For Data | 3.5 | - | All | All |
| Application | Ibm | Cloud Pak For Data | 3.5 | refresh_1 | All | All |
| Application | Ibm | Cloud Pak For Data | 3.5 | refresh_9 | All | All |
| Application | Ibm | Cloud Pak For Data | 4.0 | - | All | All |
| Application | Ibm | Cloud Pak For Data | 4.0 | refresh_1 | All | All |
| Application | Ibm | Cloud Pak For Data | 4.0 | refresh_3 | All | All |
| Application | Ibm | Cloud Pak For Data | 4.0 | refresh_4 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Data masking rules are not enforced when CREATE TABLE AS SELECT statement is executed in IBM Big SQL | CONFIRM | www.ibm.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.