Lucene search

K
ibmIBM315F5C70A72B7EF27713693482C8A40D359635BEB174A98991854730286CA3B2
HistoryDec 29, 2023 - 4:15 p.m.

Security Bulletin: Vulnerabilty in Node.js affect Cloud Pak System [CVE-2023-26155]

2023-12-2916:15:35
www.ibm.com
5
node.js
ibm cloud pak system
vulnerability
denial of service
power
upgrade
interim fix
remote attacker

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.0%

Summary

Vulnerability in node.js word-wrap affects Cloud Pak System. IBM Cloud Pak System has addressed vulnerability.

Vulnerability Details

CVEID:CVE-2023-26115
**DESCRIPTION:**Node.js word-wrap module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the result variable. By sending a specially crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/256901 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak System 2.3.1.1, 2.3.2.0 (power)
IBM Cloud Pak System 2.3.3.7 (power)

Remediation/Fixes

For unsupported or end of life release recommendation is to upgrade to supported fixed release of the product.

For IBM Cloud Pak System v2.3.1.1, v2.3.2.0, for Power
upgrade to IBM Cloud Pak System v2.3.3.7 and apply IBM Cloud Pak System v2.3.3.7 Interim Fix 1 at Fix Central.

Information on upgrading available at <https://www.ibm.com/support/pages/node/6982511&gt;

For IBM Cloud Pak System V2.3.3.7, for Power
Apply Cloud Pak System V2.3.3.7 Interim Fix 1 at Fix Central.
information on upgrading available at <http://www.ibm.com/support/docview.wss?uid=ibm10887959&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_systemMatch2.3
CPENameOperatorVersion
ibm cloud pak system softwareeq2.3

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.0%

Related for 315F5C70A72B7EF27713693482C8A40D359635BEB174A98991854730286CA3B2