Lucene search

K
ibmIBM32347A918D9AD98F0E214CD3427944E15A03E98E967C5C66362C681ADEFB0F2A
HistorySep 17, 2024 - 3:31 p.m.

Security Bulletin: IBM Security Guardium Insights is affected by multiple vulnerabilities (CVE-2024-5569, CVE-2024-39689)

2024-09-1715:31:11
www.ibm.com
22
ibm security guardium
vulnerabilities
denial of service
certifi python-certifi
update
ibm cloud pak

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7

Confidence

High

Summary

IBM Security Guardium Insights has addressed these vulnerabilities with an update.

Vulnerability Details

CVEID:CVE-2024-5569
**DESCRIPTION:**zipp is vulnerable to a denial of service, caused by an infinite loop flaw in the Path module. By using a specially crafted zip file, a local attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/297636 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2024-39689
**DESCRIPTION:**Certifi python-certifi could provide weaker than expected security, caused by the use of GLOBALTRUST root certificate. An attacker could exploit this vulnerability to launch further attacks on the system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/297375 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Guardium Insights 3.4.0

Remediation/Fixes

IBM strongly encourages customers to update their systems promptly.

Affected Product(s) Version(s) Fix
IBM Security Guardium Insights 3.4.0 Guardium Insights V3.4.1 can be downloaded as an archive file (2.4.1.tar.gz) from: https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-guardium-insights

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsecurity_guardium_insightsMatch3.4.0
VendorProductVersionCPE
ibmsecurity_guardium_insights3.4.0cpe:2.3:a:ibm:security_guardium_insights:3.4.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7

Confidence

High