CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
71.6%
The security vulnerability(heap-based buffer overflow) found in zlib was fixed in the following products: IBM Security Verify Gateway for RADIUS (v1.0.8), IBM Security Verify Gateway for Windows Login (v1.0.9) and IBM Security Verify Bridge for Directory Sync (v1.0.10)
CVEID:CVE-2022-37434
**DESCRIPTION:**zlib is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by inflate in inflate.c. By using a large gzip header extra field, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 7.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/232849 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Affected Product(s) | Version(s) |
---|---|
IBM Security Verify Gateway for Radius | 1.0.8.0 |
IBM Security Verify Gateway for Windows Login | 1.0.9.0 |
IBM Security Verify Bridge for Directory Sync | 1.0.10.0 |
IBM Security Verify Gateway for RADIUS
<https://exchange.xforce.ibmcloud.com/hub/extension/d39efc0e03582d3eed3263d7e7022058>
IBM Security Verify Gateway for Windows Login
<https://exchange.xforce.ibmcloud.com/hub/extension/103b558c1aa73755641fe45493db3301>
IBM Security Verify Bridge for Directory Sync
<https://exchange.xforce.ibmcloud.com/hub/extension/9fc025a9db848ac27640110e141429bd>
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | security_verify | 1.0.8.0 | cpe:2.3:a:ibm:security_verify:1.0.8.0:*:*:*:*:*:*:* |
ibm | security_verify | 1.0.9.0 | cpe:2.3:a:ibm:security_verify:1.0.9.0:*:*:*:*:*:*:* |
ibm | security_verify | 1.0.10.0 | cpe:2.3:a:ibm:security_verify:1.0.10.0:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
71.6%