Lucene search

K
ibmIBM13B3B0B8BDCEDC2ECAE2E204823749FF514413F1315DCAF728A1D52C05874F74
HistoryJul 07, 2023 - 2:02 p.m.

Security Bulletin: IBM DataPower Gateway affected by multiple issues in JRE

2023-07-0714:02:22
www.ibm.com
22
ibm datapower
jre
vulnerabilities
oracle java se
ibm datapower 10.0.1
ibm datapower 10.5.0
cve-2023-21930
cve-2023-21967
cve-2023-21939
cve-2023-21968
confidentiality impact
integrity impact
remote attacker
unauthenticated attacker
cve remediation
jms
ims callout
jdbc

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

51.8%

Summary

IBM has addressed the following CVEs, which potentially affect JDBC, IMS Callout and JMS components

Vulnerability Details

CVEID:CVE-2023-21930
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the JSSE component could allow an unauthenticated attacker to cause high confidentiality impact and high integrity impact.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253115 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

CVEID:CVE-2023-21967
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the Hotspot component could allow a remote attacker to cause high confidentiality impact.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253166 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2023-21939
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the Swing component could allow a remote attacker to cause integrity impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253168 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2023-21968
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE and GraalVM Enterprise Edition related to the Libraries component could allow an unauthenticated attacker to cause low integrity impact.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253083 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 10.0.1 10.0.1.0 - 10.0.1.13
IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.5
IBM DataPower Gateway 10.5 CD 10.5.1

Remediation/Fixes

Product Fixed in version APAR
IBM DataPower 10.0.1 10.0.1.14 IT44114
IBM DataPower 10.5.0 10.5.0.6 IT44114

The CVEs will be addressed in the next CD release of IBM DataPower 10.5 CD

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch10.0.1
OR
ibmdatapower_gatewayMatch10.5.0
OR
ibmdatapower_gatewayMatch10.5.1

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

51.8%