Lucene search

K
ibmIBM0E0F2CE636FE42F678E4A88F9B374E024AAECC9578165276C1C9228C8BA9E07D
HistoryOct 16, 2023 - 4:34 p.m.

Security Bulletin: Vulnerability CVE-2023-35116 affects CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition.

2023-10-1616:34:06
www.ibm.com
12
vulnerability
cics transaction gateway
multiplatforms
desktop edition
denial of service
fasterxml jackson-databind

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%

Summary

Vulnerability CVE-2023-35116 affects CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition. This fix addresses this vulnerability.

Vulnerability Details

CVEID:CVE-2023-35116
**DESCRIPTION:**Fasterxml jackson-databind is vulnerable to a denial of service, caused by a stack-based overflow. By persuading a victim to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/258157 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM CICS Transaction Gateway 9.3
CICS Transaction Gateway Desktop Edition 9.3

Remediation/Fixes

IBM recommends that you apply these fixes:

Product

| VRMF|APAR|Remediation/First Fix
—|—|—|—

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

AIX: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on Intel: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on IBM Z: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on IBM Z container: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on Intel container: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on POWER Little Endian: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Linux on POWER Big Endian: Fix Central link

CICS Transaction Gateway for Multiplatforms

CICS Transaction Gateway Desktop Edition

|

9.3

|

PH57424

|

Windows: Fix Central link

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcics_transaction_gatewayMatch9.3
CPENameOperatorVersion
cics transaction gatewayeq9.3

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%

Related for 0E0F2CE636FE42F678E4A88F9B374E024AAECC9578165276C1C9228C8BA9E07D