CVE-2022-43916Improper Restriction of Communication Channel to Intended Endpoints in IBM APP Connect Enterprise Certified Container

Severity
9.1CRITICALNVD
CNA6.8
EPSS
0.1%
top 72.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30

Description

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods that are used for internal infrastructure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

CVEListV5ibm/app_connect_enterprise_certified_container7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7

🔴Vulnerability Details

2
GHSA
GHSA-3vmp-5673-67p4: IBM App Connect Enterprise Certified Container 72025-01-30
CVEList
IBM App Connect Enterprise Certified Container improper communications restriction2025-01-30
CVE-2022-43916 — IBM vulnerability | cvebase