CVE-2022-35279
Summary
| CVE | CVE-2022-35279 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-03 20:15:00 UTC |
| Updated | 2022-11-10 14:18:00 UTC |
| Description | "IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537." |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Business Automation Workflow | 20.0.0.1 | All | All | All |
| Application | Ibm | Business Automation Workflow | 20.0.0.1 | - | All | All |
| Application | Ibm | Business Automation Workflow | 20.0.0.2 | All | All | All |
| Application | Ibm | Business Automation Workflow | 20.0.0.2 | - | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.1 | All | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.2 | All | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.2 | - | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | All | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if002 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if005 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if006 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if007 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if008 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if009 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if010 | All | All |
| Application | Ibm | Business Automation Workflow | 21.0.3 | if011 | All | All |
| Application | Ibm | Business Automation Workflow | 22.0.1 | All | All | All |
| Application | Ibm | Business Automation Workflow | 22.0.1 | - | All | All |
| Application | Ibm | Business Automation Workflow | 22.0.1 | if001 | All | All |
| Application | Ibm | Business Automation Workflow | All | All | All | All |
| Application | Ibm | Business Automation Workflow | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Information disclosure vulnerability affect IBM Business Automation Workflow - CVE-2022-35279 | MISC | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.