CVE-2022-40153: High severity IBM Watson Studio on Cloud Pak for Data vulnerability
REJECT DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
Other sources
A flaw was found in the XStream package. This flaw allows an attacker to cause a denial of service (DoS) in its target via XML serialization.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
— IBM
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=49858 https://github.com/x-stream/xstream/issues/304
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-40153.
What is the severity of CVE-2022-40153?
CVE-2022-40153 has a severity of high.
What is the impact of CVE-2022-40153?
CVE-2022-40153 allows an attacker to cause a denial of service.
Are there any known exploits for CVE-2022-40153?
There are no known exploits for CVE-2022-40153 at the moment.
How can I mitigate the risk posed by CVE-2022-40153?
To mitigate the risk posed by CVE-2022-40153, it is recommended to update to the latest version of the XStream package.