Details
-
Fix
-
Status: Released (View Workflow)
-
Medium
-
Resolution: Fixed
-
2.0.0
-
None
-
CVE-2022-21510
Description
Current Situation
- JS7 (JobScheduler branch 2.x) Agent and JOC Cockpit Web Services ship with the Oracle JDBC Driver 21.8.0.0.
- A vulnerability communicated by a CVE advisory affects this version,
- see https://nvd.nist.gov/vuln/detail/CVE-2022-21510 for more information on the impact.
- Risk Mitigation
The issue is rated high by CVE.
We rate the impact to our software as low as the attack scenario described works only with administrative access to servers operating JOC Cockpit and Agents.
Desired Behavior
- JobScheduler releases 2.6.0 and 2.5.4 ship with Oracle JDBC Driver 19.19.0.0.