CVE-2022-40609
02.08.2023, 15:15
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | sdk | 𝑥 < 7.1.5.19 |
| ibm | sdk | 8.0 ≤ 𝑥 < 8.0.8.5 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| java-1.8.0-ibm |
| ||||||||||||
| java-1.8.0-ibm-demo |
| ||||||||||||
| java-1.8.0-ibm-devel |
| ||||||||||||
| java-1.8.0-ibm-headless |
| ||||||||||||
| java-1.8.0-ibm-jdbc |
| ||||||||||||
| java-1.8.0-ibm-plugin |
| ||||||||||||
| java-1.8.0-ibm-src |
| ||||||||||||
| java-1.8.0-ibm-webstart |
|
Common Weakness Enumeration