The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this issue by reducing the amount of time the sensitive data is visible in memory. IBM X-Force ID: 241675.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2023-04-07T13:37:22.306Z
Updated: 2024-08-03T13:40:06.598Z
Reserved: 2022-10-26T15:46:22.849Z
Link: CVE-2022-43928
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-07T14:15:07.360
Modified: 2024-11-21T07:27:22.377
Link: CVE-2022-43928
Redhat
No data.