Lucene search

K
ibmIBM39483C1D88EDE6E1217BE5AE44B5E429C17BC3FFB232291B8DF1B1B982203088
HistoryFeb 13, 2023 - 9:56 p.m.

Security Bulletin: IBM Sterling Control Center is vulnerable to a denial of service due to Jave SE (CVE-2022-21626)

2023-02-1321:56:47
www.ibm.com
13
ibm sterling control center
java se
denial of service
vulnerability
unauthenticated attacker

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

52.9%

Summary

An unspecified vulnerability in Java SE related to the Security component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.

Vulnerability Details

CVEID:CVE-2022-21626
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Security component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/238689 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Sterling Control Center 6.1.3
IBM Sterling Control Center 6.2.1.0
IBM Sterling Control Center 6.3.0

Remediation/Fixes

Product

|

Version

|

Remediation

—|—|—

IBM Sterling Control Center

|

6.1.3.0 GA through iFix14

|

6.1.3.0 iFix15 Fix Central - 6.1.3.0

IBM Sterling Control Center

|

6.2.1.0 GA through iFix09

|

6.2.1.0 iFix10 Fix Central - 6.2.1.0

IBM Sterling Control Center

|

6.3.0.0 GA

|

6.3.0.0 iFix01 Fix Central - 6.3.0.0

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcontrol_centerMatch6.3.0.0
OR
ibmcontrol_centerMatch6.2.1.0
OR
ibmcontrol_centerMatch6.1.3.0
VendorProductVersionCPE
ibmcontrol_center6.3.0.0cpe:2.3:a:ibm:control_center:6.3.0.0:*:*:*:*:*:*:*
ibmcontrol_center6.2.1.0cpe:2.3:a:ibm:control_center:6.2.1.0:*:*:*:*:*:*:*
ibmcontrol_center6.1.3.0cpe:2.3:a:ibm:control_center:6.1.3.0:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

52.9%