CVE-2022-40609

IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.  IBM X-Force ID:  236069.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
ibmsdk
𝑥
< 7.1.5.19
ibmsdk
8.0 ≤
𝑥
< 8.0.8.5
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.8.0-ibm
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-demo
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-devel
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-headless
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-jdbc
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-plugin
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-src
RHEL 7
1:1.8.0.8.5-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed
java-1.8.0-ibm-webstart
RHEL 8
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 AUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 E4S
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 EUS
1:1.8.0.8.5-1.el8_8
fixed
RHEL 8.8 TUS
1:1.8.0.8.5-1.el8_8
fixed