SB2022092641 - Multiple vulnerabilities in IBM Tivoli Netcool Impact
Published: September 26, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2022-26520)
The vulnerability allows a remote attacker to create arbitrary files on the system.
The vulnerability exists due to insufficient validation of user-supplied input when handling jdbc URL or its properties. A remote attacker can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties.
Successful exploitation of the vulnerability may allow an attacker to create and executable arbitraru JSP file under a Tomcat web root.
2) Improper initialization (CVE-ID: CVE-2022-21724)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to improper initialization in pgjdbc driver when handling attacker-controlled URL in connection properties as the driver does not verify if the class implements the expected interface before instantiating the class. A remote attacker can pass specially crafted URL to the affected application and execute arbitrary code in the system.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-postgresql-shipped-with-ibm-tivoli-netcool-impact-cve-2022-26520-cve-2022-21724-220313/"
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-postgresql-shipped-with-ibm-tivoli-netcool-impact-cve-2022-26520-cve-2022-21724-220313/</a></p><p>
- https://www.ibm.com/support/pages/node/6602599</p><p><br></p>