Lucene search

K
ibmIBM09F1A9653F919F12354F2986578D73A8BEC4B9F52CB4AC4A67D6822A5C04F932
HistoryDec 15, 2023 - 1:02 p.m.

Security Bulletin: Vulnerabilities in cryptography affect IBM Spectrum Sentinel Anomaly Scan Engine (239927)

2023-12-1513:02:29
www.ibm.com
5
ibm spectrum sentinel
cryptography vulnerabilities
buffer overflow
remote code execution
ibm storage sentinel anomaly scan engine
ibm support pages.

AI Score

8.2

Confidence

High

Summary

Vulnerabilities in python cryptography affect IBM Spectrum Sentinel Anomaly Scan Engine. Vulnerabilities include: Python cryptography allowing remote attacker to overflow a buffer and execute arbitrary code on the system. This bulletin identifies the steps to take to address the vulnerability.

Vulnerability Details

**IBM X-Force ID:**239927
**DESCRIPTION:**Python Cryptographic Authority cryptography is vulnerable to a buffer overflow, caused by improper bounds checking by the OpenSSL library. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/239927 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Sentinel Anomaly Scan Engine 1.1.0 - 1.1.5

Remediation/Fixes

IBM Spectrum Sentinel Anomaly Scan Engine

|

Fixing Level

|

Platform

|

Link to Fix and Instructions

—|—|—|—

1.1.0-1.1.5

|

1.1.6

|

Linux

|

<https://www.ibm.com/support/pages/node/7070601&gt;

Please refer to IBM Spectrum Copy Data Management security bulletins for the Spectrum Copy Data Management vulnerabilities.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_storage_sentinelMatch1.1
VendorProductVersionCPE
ibmibm_storage_sentinel1.1cpe:2.3:a:ibm:ibm_storage_sentinel:1.1:*:*:*:*:*:*:*

AI Score

8.2

Confidence

High