Lucene search

K
ibmIBM34C7791F8053F12D825D0D3020EBA83D3FF3378E4AC6DDB6B9A311E2FB46A6CA
HistorySep 18, 2024 - 7:55 p.m.

Security Bulletin: Vulnerability in Perl affects IBM watsonx.data

2024-09-1819:55:13
www.ibm.com
2
perl
ibm watsonx.data
vulnerability
regcomp.c
cvss 9.8
remote attacker
security restrictions

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low

Summary

Perl could allow a remote attacker to bypass security restrictions, caused by improper handling of property name by the S_parse_uniprop_string function in regcomp.c. This can affect IBM watsonx.data.

Vulnerability Details

CVEID:CVE-2023-47100
**DESCRIPTION:**Perl could allow a remote attacker to bypass security restrictions, caused by improper handling of property name by the S_parse_uniprop_string function in regcomp.c. By using a specially crafted regular expression input, an attacker could exploit this vulnerability to write to unallocated space.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/272992 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM watsonx.data 1.1.3

Remediation/Fixes

The product needs to be installed or upgraded to the latest available level watsonx.data 2.0.2 or watsonx.data on CPD 5.0.2. Installation/upgrade instructions can be found here: <https://www.ibm.com/docs/en/watsonx/watsonxdata/2.0.x?topic=deployment-installing&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_watsonx_subscriptionMatch1.1.3
VendorProductVersionCPE
ibmibm_watsonx_subscription1.1.3cpe:2.3:a:ibm:ibm_watsonx_subscription:1.1.3:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low