Security Advisory: IDMS Server - CVE-2022-1292

IDMS Server

22209

31 May 2023

31 May 2023

CLOSED

HIGH

7.5

2022-1292

Broadcom Mainframe Software is alerting customers to a vulnerability in IDMS Server 17.1

If you are not using SSL with the IDMS ODBC driver, this advisory does not apply.

Product Name

 IDMS Server 17.1

SEVERITY:

 HIGH

CVE:     (optional)

 CVE-2022-1292

CVSS Score

 Base 7.5  Temporal 6.5

CVSS Vector

 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

SOLUTION:

 LU10148

PLATFORM(s):

 Windows

AFFECTED COMPONENTS:

OpenSSL component upgraded from 1.1.1q to 1.1.1t in IDMS ODBC driver version 17.1.9

 

Broadcom customers may receive alerts and advisories by subscribing to Proactive Notifications.

If you missed any Mainframe Security Advisory alerts you can find all under Mainframe Security Advisories on the customer support portal.

Broadcom SECINT HOLDDATA is incorporated into our standard HOLDDATA file downloads. Therefore, it is not necessary to download any additional HOLDDATA files. Broadcom does recommend that you use SMP/E Receive Order to acquire HOLDDATA and maintenance.

Customers who require additional information about this notice may contact Broadcom Support at: Support.Broadcom.com.

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." For an explanation of the CVSS scoring system and a description of each metric, please visit https://www.first.org/cvss/v3.1/specification-document

BROADCOM PROVIDES THE CVSS BASE AND TEMPORAL SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY IN THEIR SPECIFIC ENVIRONMENT. BROADCOM DOES NOT PROVIDE A CVSS ENVIRONMENT SCORE. THE CVSS ENVIRONMENT SCORE IS CUSTOMER ENVIRONMENT SPECIFIC AND WILL IMPACT THE OVERALL CVSS SCORE. CUSTOMERS SHOULD EVALUATE THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY AND CAN CALCULATE A CVSS ENVIRONMENT SCORE.

The CVSS score and all other information describing the security matter is Broadcom confidential and may be used by you for internal purposes only and may not be disclosed to any third party without Broadcom's prior written consent.