Lucene search

K
ibmIBM3E07C2DE7AC309319BAAF6FF4AECE19884B3BBA081A6C0ECB9E3722A8C5B9B7F
HistoryJan 12, 2023 - 9:59 p.m.

Security Bulletin: IBM WebSphere Application Server Vulnerability Affects Watson Speech Services

2023-01-1221:59:00
www.ibm.com
14
ibm
websphere
vulnerability
watson speech services
cloud pak
data
cve-2021-29842
liberty
x-force

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

42.7%

Summary

An IBM WebSphere Application Server (Liberty) Vulnerability affecting Watson Speech Services has been fixed in the latest version of IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.3

Vulnerability Details

CVEID:CVE-2021-29842
**DESCRIPTION:**IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/205202 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.3

Remediation/Fixes

Download and install the newest deployment of IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data to your ICP cluster. This deployment contains the upgrade to liberty 21.0.0_10 or higher, that fixes this issue.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_securityMatch1.0.0
OR
ibmcloud_pak_for_securityMatch4.0.3
VendorProductVersionCPE
ibmcloud_pak_for_security1.0.0cpe:2.3:a:ibm:cloud_pak_for_security:1.0.0:*:*:*:*:*:*:*
ibmcloud_pak_for_security4.0.3cpe:2.3:a:ibm:cloud_pak_for_security:4.0.3:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

42.7%

Related for 3E07C2DE7AC309319BAAF6FF4AECE19884B3BBA081A6C0ECB9E3722A8C5B9B7F