Lucene search

K
ibmIBM1E9676FF5F81DEBE7C7867D40C3F4E64CD69C80E5A5C15174D65DF2F4FA381F3
HistoryMar 13, 2024 - 10:19 a.m.

Security Bulletin: Due to the use of IBM WebSphere Liberty, IBM TXSeries for Multiplatforms is vulnerable to a flaw in handling multiplexed streams in the HTTP/2 protocol (CVE-2023-44487).

2024-03-1310:19:14
www.ibm.com
27
ibm
websphere liberty
txseries for multiplatforms
vulnerability
http/2 protocol
cve-2023-44487
upgrade

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0.813

Percentile

98.4%

Summary

IBM WebSphere Liberty is used by IBM TXSeries for Multiplatforms to provide a web based administration console (CVE-2023-44487).

Vulnerability Details

CVEID:CVE-2023-44487
**DESCRIPTION:**Multiple vendors are vulnerable to a denial of service, caused by a flaw in handling multiplexed streams in the HTTP/2 protocol. By sending numerous HTTP/2 requests and RST_STREAM frames over multiple streams, a remote attacker could exploit this vulnerability to cause a denial of service due to server resource consumption.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268044 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM TXSeries for Multiplatforms 8.1
IBM TXSeries for Multiplatforms 8.2
IBM TXSeries for Multiplatforms 9.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading IBM CICS TXSeries for Multiplatforms.

Product Version Platform Remediation/Fix
IBM TXSeries for Multiplatforms 8.1 Linux, AIX

PSIRT fixes for TXSeries 8.1 will be provided only for extended support customers with a request through Salesforce case

IBM TXSeries for Multiplatforms| 8.2| Linux, Windows, AIX| Download the upgrade from Fix Central
IBM TXSeries for Multiplatforms| 9.1| Linux, AIX| Download the upgrade from Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtxseries_for_multiplatformsMatch8.1
OR
ibmtxseries_for_multiplatformsMatch8.2
OR
ibmtxseries_for_multiplatformsMatch9.1
VendorProductVersionCPE
ibmtxseries_for_multiplatforms8.1cpe:2.3:a:ibm:txseries_for_multiplatforms:8.1:*:*:*:*:*:*:*
ibmtxseries_for_multiplatforms8.2cpe:2.3:a:ibm:txseries_for_multiplatforms:8.2:*:*:*:*:*:*:*
ibmtxseries_for_multiplatforms9.1cpe:2.3:a:ibm:txseries_for_multiplatforms:9.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0.813

Percentile

98.4%