CVE-2022-40609
published 2023-08-02CVE-2022-40609: IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.83%
76.6th percentile
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sdk | < 7.1.5.19 | 7.1.5.19 |
| ibm | sdk | >= 8.0 < 8.0.8.5 | 8.0.8.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unsafe deserialization flaw in the Object Request Broker (ORB)
vendor_redhat·2023-08-01·CVSS 8.1
CVE-2022-40609 [HIGH] CWE-502 JDK: unsafe deserialization flaw in the Object Request Broker (ORB)
JDK: unsafe deserialization flaw in the Object Request Broker (ORB)
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.
A flaw was found in IBM SDK, Java Technology Edition, which could allow a remote attacker to execute arbitrary code on the system caused by an unsafe deserialization flaw. An attacker could exploit this vulnerability by sending specially-crafted data to execute arbitrary code on the system.
Package: java-1.7.1-ibm (Red Hat Enterprise Linux 7) - Out of support scope
GHSA
GHSA-2cf4-9q4p-f6wj: IBM SDK, Java Technology Edition 7
ghsa_unreviewed·2023-08-02
CVE-2022-40609 [CRITICAL] CWE-502 GHSA-2cf4-9q4p-f6wj: IBM SDK, Java Technology Edition 7
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-02
Published