Lucene search

K
ibmIBM1DB0458AB887589B461C08A64B9EA32BD7BF02B66E76B467DC786D016835017A
HistoryAug 08, 2023 - 8:43 p.m.

Security Bulletin: Certifi component is vulnerable to CVE-2022-23491 used by IBM Maximo Application Suite

2023-08-0820:43:37
www.ibm.com
15
ibm maximo application suite
certifi
cve-2022-23491
trustcor's ownership
fixpack
spyware

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

23.8%

Summary

IBM Maximo Application Suite uses Certifi which is vulnerable to CVE-2022-23491.

Vulnerability Details

CVEID:CVE-2022-23491
**DESCRIPTION:**An unspecified error in with TrustCor’s ownership also operated a business that produced spyware in Certifi has an unknown impact and attack vector.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/241627 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Maximo Application Suite 8.8
IBM Maximo Application Suite 8.9

Remediation/Fixes

Affected Product(s) Fixpack Version(s)
IBM Maximo Application Suite 8.8.7 or the latest (available from the Catalog under Update Available)
IBM Maximo Application Suite 8.9.3 or the latest (available from the Catalog under Update Available)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch8.8
OR
ibmmaximo_application_suiteMatch8.9

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

23.8%