Vulnerability Name:

CVE-2022-21549 (CCN-231575)

Assigned:2021-11-15
Published:2022-07-19
Updated:2023-04-27
Summary:
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Other
References:Source: MITRE
Type: CNA
CVE-2022-21549

Source: XF
Type: UNKNOWN
oracle-cpujul2022-cve202221549(231575)

Source: secalert_us@oracle.com
Type: Mailing List, Third Party Advisory
secalert_us@oracle.com

Source: secalert_us@oracle.com
Type: Mailing List, Third Party Advisory
secalert_us@oracle.com

Source: secalert_us@oracle.com
Type: Third Party Advisory
secalert_us@oracle.com

Source: secalert_us@oracle.com
Type: Third Party Advisory
secalert_us@oracle.com

Source: CCN
Type: IBM Security Bulletin 6618705 (Semeru Runtimes)
Multiple vulnerabilities may affect IBM Semeru Runtime

Source: CCN
Type: IBM Security Bulletin 6695887 (z/Transaction Processing Facility)
Multiple vulnerabilities in IBM Semeru Runtime affect z/Transaction Processing Facility

Source: CCN
Type: IBM Security Bulletin 6828537 (Robotic Process Automation)
Multiple security vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak

Source: CCN
Type: Oracle CPUJul2022
Oracle Critical Patch Update Advisory - July 2022

Source: secalert_us@oracle.com
Type: Patch, Vendor Advisory
secalert_us@oracle.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/a:redhat:enterprise_linux:9:*:*:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/a:redhat:enterprise_linux:9::appstream:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/a:redhat:enterprise_linux:9::crb:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:graalvm:21.3.2:*:*:*:enterprise:*:*:*
  • OR cpe:/a:oracle:graalvm:22.1.0:*:*:*:enterprise:*:*:*
  • AND
  • cpe:/a:ibm:robotic_process_automation:21.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation:21.0.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7536
    P
    java-17-openjdk-17.0.7.0-150400.3.18.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8079
    P
    java-1_8_0-ibm-1.8.0_sr8.0-150000.3.71.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:718
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-31
    oval:org.opensuse.security:def:6120
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119664
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-31
    oval:org.opensuse.security:def:5312
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:125770
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:127331
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119479
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-31
    oval:org.opensuse.security:def:125786
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:127346
    P
    Security update for java-1_7_1-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:126948
    P
    Security update for java-1_7_1-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:6145
    P
    Security update for java-1_7_1-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:127347
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:5330
    P
    Security update for java-1_7_1-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:126949
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:6146
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:125785
    P
    Security update for java-1_7_1-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:5331
    P
    Security update for java-1_8_0-ibm (Important)
    2022-08-25
    oval:org.opensuse.security:def:3663
    P
    Security update for java-17-openjdk (Important)
    2022-08-03
    oval:org.opensuse.security:def:672
    P
    Security update for java-17-openjdk (Important)
    2022-08-03
    oval:org.opensuse.security:def:95293
    P
    Security update for java-17-openjdk (Important)
    2022-08-03
    oval:com.redhat.rhsa:def:20225736
    P
    RHSA-2022:5736: java-17-openjdk security, bug fix, and enhancement update (Important)
    2022-07-27
    oval:com.redhat.rhsa:def:20225726
    P
    RHSA-2022:5726: java-17-openjdk security, bug fix, and enhancement update (Important)
    2022-07-26
    BACK
    oracle graalvm 21.3.2
    oracle graalvm 22.1.0
    ibm robotic process automation 21.0.1
    ibm robotic process automation 21.0.2
    ibm robotic process automation 21.0.3
    ibm robotic process automation 21.0.4