CVE-2022-40746
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.
IBM i Access Family 1.1.2 a 1.1.4 y 1.1.4.3 a 1.1.9.0 podría permitir que un atacante autenticado local ejecute código arbitrario en el sistema, causado por una vulnerabilidad de secuestro de orden de búsqueda de DLL. Al colocar un archivo especialmente manipulado en una carpeta comprometida, un atacante podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el sistema. ID de IBM X-Force: 236581.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-16 CVE Reserved
- 2022-11-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/pages/node/6840359 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/236581 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | I Access Client Solutions Search vendor "Ibm" for product "I Access Client Solutions" | >= 1.1.2 <= 1.1.4 Search vendor "Ibm" for product "I Access Client Solutions" and version " >= 1.1.2 <= 1.1.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Ibm Search vendor "Ibm" | I Access Client Solutions Search vendor "Ibm" for product "I Access Client Solutions" | >= 1.1.4.3 <= 1.1.9.0 Search vendor "Ibm" for product "I Access Client Solutions" and version " >= 1.1.4.3 <= 1.1.9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|