Multiple vulnerabilities in IBM Watson Explorer



Published: 2022-06-22
Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2022-22475
CVE-2021-39038
CWE-ID CWE-287
CWE-451
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
IBM Watson Explorer Analytical Components
Client/Desktop applications / Software for system administration

IBM Watson Explorer Foundational Components
Client/Desktop applications / Software for system administration

IBM Watson Explorer Deep Analytics Edition oneWEX
Client/Desktop applications / Software for system administration

IBM Watson Explorer Deep Analytics Edition Analytical Components
Client/Desktop applications / Software for system administration

IBM Watson Explorer Deep Analytics Edition Foundational Components
Client/Desktop applications / Software for system administration

Vendor IBM Corporation

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Improper Authentication

EUVDB-ID: #VU64197

Risk: Low

CVSSv3.1: 5.5 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-22475

CWE-ID: CWE-287 - Improper Authentication

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to an unspecified error. A remote authenticated user can spoof identity of other application users.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Watson Explorer Analytical Components: 11.0.0.3 - 11.0.2.13

IBM Watson Explorer Foundational Components: 11.0.0.3 - 11.0.2.13

IBM Watson Explorer Deep Analytics Edition oneWEX: 12.0.0.0 - 12.0.3.9

IBM Watson Explorer Deep Analytics Edition Analytical Components: 12.0.0.0 - 12.0.3.9

IBM Watson Explorer Deep Analytics Edition Foundational Components: 12.0.0.0 - 12.0.3.9

External links

http://www.ibm.com/support/pages/node/6591057


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Spoofing attack

EUVDB-ID: #VU60870

Risk: Low

CVSSv3.1: 3.7 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-39038

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform clickjacking attack.

The vulnerability exists due to incorrect processing of user-supplied data, when REST API discovery is configured through the WebSphere administrative console Web Container settings to enable the API Discovery service, or through IBM WebSphere Application Server Liberty features mpOpenAPI-1.0, mpOpenAPI-1.1, mpOpenAPI-2.0, apiDiscovery-1.0, openapi-3.0 or openapi-3.1. A remote attacker can perform clickjacking attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Watson Explorer Analytical Components: 11.0.0.3 - 11.0.2.13

IBM Watson Explorer Foundational Components: 11.0.0.3 - 11.0.2.13

IBM Watson Explorer Deep Analytics Edition oneWEX: 12.0.0.0 - 12.0.3.9

IBM Watson Explorer Deep Analytics Edition Analytical Components: 12.0.0.0 - 12.0.3.9

IBM Watson Explorer Deep Analytics Edition Foundational Components: 12.0.0.0 - 12.0.3.9

External links

http://www.ibm.com/support/pages/node/6591057


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###