IBM Support

Is JazzSM/DASH affected by CVE-2022-42889 and CVE-2022-36067?

Question & Answer


Question

Is JazzSM/DASH affected by CVE-2022-42889 and CVE-2022-36067?

Answer

DASH does not use Apache Commons Text and vm2. So, DASH is not affected by these vulnerabilities.

https://nvd.nist.gov/vuln/detail/CVE-2022-42889

https://nvd.nist.gov/vuln/detail/CVE-2022-36067

[{"Type":"MASTER","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEKCU","label":"Jazz for Service Management"},"ARM Category":[{"code":"a8m500000008bt0AAA","label":"DASH-\u003EDASH UI Services - Security Category-\u003EDUIS-Security - Attack Vulnerability issues"}],"ARM Case Number":"TS010954551","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
21 October 2022

UID

ibm16831217