CVE-2022-34350
Published on: Not Yet Published
Last Modified on: 02/23/2023 05:13:00 AM UTC
Certain versions of Api Connect from Ibm contain the following vulnerability:
IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 230264.
- CVE-2022-34350 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
IBM - API Connect version = 10.0.0.0
- Affected Vendor/Software:
IBM - API Connect version = 10.0.1.0
- Affected Vendor/Software:
IBM - API Connect version = 2018.4.1.0
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Bulletin: IBM API Connect is impacted by an external service interaction vulnerability (CVE-2022-34350) | www.ibm.com text/html |
![]() |
IBM X-Force Exchange | exchange.xforce.ibmcloud.com text/html |
![]() |
Exploit/POC from Github
IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerabl…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Ibm | Api Connect | All | All | All | All |
Application | Ibm | Api Connect | All | All | All | All |
Application | Ibm | Api Connect | All | All | All | All |
- cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*:
- cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*:
- cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-34350 : #IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018… twitter.com/i/web/status/1… | 2023-02-08 20:01:39 |
![]() |
CVE-2022-34350 | 2023-02-08 21:38:42 |