Lucene search

K
ibmIBM07DDA3B4F1EBFDED1DD43706D337A38C466ED5848453C259AADD9AE495FAC755
HistoryJan 26, 2024 - 10:04 p.m.

Security Bulletin: IBM Storage Ceph is vulnerable to Uncontrolled Resource Consumption in Ceph (CVE-2023-46159)

2024-01-2622:04:48
www.ibm.com
22
ibm storage ceph
vulnerability
fix
upgrade
download
rgw
denial of service
authenticated user
ceph

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

Summary

Ceph is used by IBM Storage Ceph as storage. CVE-2023-46159 This bulletin identifies the steps to take to address the vulnerability in Ceph.

Vulnerability Details

CVEID:CVE-2023-46159
**DESCRIPTION:**IBM Storage Ceph could allow an authenticated user on the network to cause a denial of service from RGW.
CVSS Base score: 2.6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268906 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Ceph <6.1z2
IBM Storage Ceph 5.3z1-z5

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.
Download the latest version of IBM Storage Ceph and upgrade to 6.1z2 by following instructions.

<https://public.dhe.ibm.com/ibmdl/export/pub/storage/ceph/&gt;
<https://www.ibm.com/docs/en/storage-ceph/6?topic=upgrading&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmstorage_cephMatch5.3
OR
ibmstorage_cephMatch1
OR
ibmstorage_cephMatch5
OR
ibmstorage_cephMatch6.1
OR
ibmstorage_cephMatch1

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

Related for 07DDA3B4F1EBFDED1DD43706D337A38C466ED5848453C259AADD9AE495FAC755