← Vulnerability feed

Vulnerability record · CVE-2022-22454 · published 10 May 2022

CVE-2022-22454: Ibm infosphere information server on cloud os command injection vulnerability

Ibm · Infosphere Information Server On Cloud

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

7.8 CVSS 3.1 High EPSS 0.36% · top 72.3% CWE-78 · OS command injection
7.8CVSS 3.1 base score, v2 7.2
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22454 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40689Ibm infosphere information server sql injection vulnerabilityIBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…EPSS 0.54%9.8CVE-2022-40752Ibm infosphere information server command injection vulnerabilityIBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …EPSS 1.8%9.8CVE-2018-1994Ibm infosphere information server on cloud sql injection vulnerabilityIBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which …EPSS 1.6%8.8CVE-2020-4305Ibm infosphere information server deserialization of untrusted data vulnerabilityIBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deseriali…EPSS 4.5%8.5CVE-2018-1701Ibm infosphere information server vulnerabilityIBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process…EPSS 1.2%8.3CVE-2019-4185Ibm infosphere information server vulnerabilityIBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID:…EPSS 0.59%8.1CVE-2016-6059Ibm infosphere datastage xml external entity (xxe) vulnerabilityIBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…EPSS 1.5%7.1CVE-2018-1845Ibm infosphere information server xml external entity (xxe) vulnerabilityIBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2022-22454), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.