Lucene search

K
ibmIBM407C5BA6F87D87480BE2E35485ACB27324098C08D9473ABCDC85674836045459
HistoryOct 20, 2022 - 11:29 a.m.

Security Bulletin: Vulnerability found in Eclipse Jetty may affect IBM Enterprise Records

2022-10-2011:29:10
www.ibm.com
14
ibm enterprise records
eclipse jetty
vulnerability
denial of service
cpu resources
cve-2021-28165
ibm cloud
version 5.2.x

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.802 High

EPSS

Percentile

98.3%

Summary

IBM Enterprise Records may be affected by vulnerability found in Eclipse Jetty.

Vulnerability Details

CVEID:CVE-2021-28165
**DESCRIPTION:**Eclipse Jetty is vulnerable to a denial of service, caused by improper input valistion. By sending a specially-crafted TLS frame, a remote attacker could exploit this vulnerability to cause CPU resources to reach to 100% usage.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199305 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Enterprise Records 5.2.x

Remediation/Fixes

Product VRM Remediation
IBM Enterprise Records 5.2.1

Use IBM Enterprise Records 5.2.1.8 IF002

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmenterprise_recordsMatch5.2.1
CPENameOperatorVersion
enterprise recordseq5.2.1

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.802 High

EPSS

Percentile

98.3%