Lucene search

K
ibmIBM35FF82BD3B49CC153E38351AA7C9C094D39A5D39F1F02E664ACB627E3FF50039
HistoryAug 29, 2023 - 5:31 a.m.

Security Bulletin: The IBM® Engineering Lifecycle Engineering product using IBM SDK, Java Technology Edition Quarterly CPU - Apr 2023 - Includes Oracle April 2023 CPU is vulnerable to (CVE-2023-2597)

2023-08-2905:31:24
www.ibm.com
27
ibm
engineering lifecycle
requirements quality assistant
java technology
oracle
cve-2023-2597
vulnerability
security bulletin

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.001 Low

EPSS

Percentile

48.3%

Summary

All appicable Java SE CVEs published by Oracle as part of their April 2023 Critical Patch Update, plus CVE-2023-2597. Following IBM® Engineering Lifecycle Engineering product is vulnerable to this attack, it has been addressed in this bulletin: IBM Engineering Requirements Quality Assistant On-Premises

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) ** Version(s)**
IBM Engineering Requirements Quality Assistant On-Premises 3.1

Remediation/Fixes

CVE-2023-2597 may affect IBM Engineering Requirements Quality Assistant On-Premises, which uses IBM SDK, Java Technology Edition Quarterly CPU - Apr 2023.

If this product is deployed on one of the above version, Please follow the instruction given in the following article.

Link: <https://www.ibm.com/support/pages/node/7001663&gt;

How to update the IBM SDK for Java of Engineering Lifecycle Management products? Please refer below article for more details.

<https://www.ibm.com/support/pages/how-update-ibm-sdk-java-engineering-lifecycle-management-products&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_engineering_lifecycle_management_baseMatch6.0.6
OR
ibmibm_engineering_lifecycle_management_baseMatch6.0.6.1
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0.1
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0.2

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.001 Low

EPSS

Percentile

48.3%

Related for 35FF82BD3B49CC153E38351AA7C9C094D39A5D39F1F02E664ACB627E3FF50039