CVE-2022-43901

MEDIUM

IBM WebSphere Automation <1.4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/6842605
Broken Link, VDB Entry, Vendor Advisory vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/240829

Scores

CVSS v3 5.7
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-668
Status published
Products (1)
ibm/websphere_automation_for_ibm_cloud_pak_for_watson_aiops < 1.4.3
Published Dec 01, 2022
Tracked Since Feb 18, 2026