Lucene search

K
ibmIBM01D6BA94CF18FFE2EFF5CFFDAD3FA8034128F071DFE5599350CE1B6748C7BBC8
HistoryJul 25, 2023 - 6:01 a.m.

Security Bulletin: IBM Security Verify Governance - Identity Manager Virtual Appliance has multiple vulnerabilities (CVE-2023-35019, CVE-2023-35016)

2023-07-2506:01:00
www.ibm.com
30
ibm
security
vulnerabilities
identity manager
virtual appliance
cve-2023-35019
cve-2023-35016
remedy

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

48.0%

Summary

Multiple security vulnerabilities have been addressed in IBM Security Verify Governance, Identity Manager - Virtual Appliance component.

Vulnerability Details

CVEID:CVE-2023-35019
**DESCRIPTION:**IBM Security Verify Governance, Identity Manager could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/257873 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2023-35016
**DESCRIPTION:**IBM Security Verify Governance, Identity Manager could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing “dot dot” sequences (/…/) to view arbitrary files on the system.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/257772 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Verify Governance, Identity Manager virtual appliance component All

Remediation/Fixes

IBM recommends customers update their systems promptly by downloading the following fix pack:

Affected Product(s) Version(s) Fix Availability
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1

10.0.1.0-ISS-ISVG-IMVA-FP0005

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsecurity_verify_governanceMatch10.0
VendorProductVersionCPE
ibmsecurity_verify_governance10.0cpe:2.3:a:ibm:security_verify_governance:10.0:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

48.0%

Related for 01D6BA94CF18FFE2EFF5CFFDAD3FA8034128F071DFE5599350CE1B6748C7BBC8