Rewterz Threat Alert – BabyElephant APT Targeting Bangladesh Navy – Active IOCs
April 1, 2022Rewterz Threat Advisory – CVE-2022-24066 – Node.js simple-git module Vulnerability
April 4, 2022Rewterz Threat Alert – BabyElephant APT Targeting Bangladesh Navy – Active IOCs
April 1, 2022Rewterz Threat Advisory – CVE-2022-24066 – Node.js simple-git module Vulnerability
April 4, 2022Severity
Medium
Analysis Summary
CVE-2022-22404 CVSS:6.5
IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting.
CVE-2022-22332 CVSS:5.6
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
CVE-2022-22331 CVSS:5.4
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR).
CVE-2022-22328 CVSS:6.2
IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data.
CVE-2022-22327 CVSS:5.9
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Impact
- Denial of Service
- Privilege Escalation
- Information Theft
Indicator Of Compromise
CVE
- CVE-2022-22404
- CVE-2022-22332
- CVE-2022-22331
- CVE-2022-22328
- CVE-2022-22327
Affected Vendors
IBM
Affected Products
- IBM App Connect Enterprise Certified Container 1.5
- IBM App Connect Enterprise Certified Container 2.0
- IBM App Connect Enterprise Certified Container 2.1
- IBM App Connect Enterprise Certified Container 3.0
- IBM Sterling Partner Engagement Manager 6.2.0
- BM UrbanCode Deploy 7.0.5
- IBM UrbanCode Deploy 7.1.0
- IBM UrbanCode Deploy 7.1.1
- IBM UrbanCode Deploy 7.1.2
Remediation
Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.
CVE-2022-22404
CVE-2022-22332
CVE-2022-22331
CVE-2022-22328
CVE-2022-22327