IBM Alert
2925Warning Date
Severity Level
Warning Number
Target Sector
13 September, 2022
● High
2022-5229
All
IBM has released security updates to address several vulnerabilities in several products:
- AIX
- IBM WebSphere Application Server Liberty for IBM i
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- Spoofing attacks
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-aix-is-vulnerable-to-a-privilege-escalation-vulnerability-due-to-invscout-cve-2022-36768/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-websphere-application-server-liberty-for-ibm-i-is-vulnerable-to-identity-spoofing-with-authenticated-user-and-ability-to-bypass-security-restrictions-due-to-eclipse-paho-java-cl/
- https://www.ibm.com/blogs/psirt/security-bulletin-aix-is-vulnerable-to-a-privilege-escalation-vulnerability-cve-2022-34356/