Lucene search

K
ibmIBM412DD21995BA29E0CA8EAC1227DBCC22821A51593DB96420F2A8085503D0DBAB
HistoryJan 16, 2024 - 7:08 a.m.

Security Bulletin: [All] Apache Tomcat (core only) - CVE-2023-45648 (Publicly disclosed vulnerability)

2024-01-1607:08:12
www.ibm.com
14
apache tomcat
http request smuggling
ibm power hmc
cve-2023-45648
vulnerability
xss attacks
web cache
web application firewall
fix central
ibm fix
cvss score
version 10.1.1010.0
version 10.2.1030.0
version 10.3.1050.0

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

60.5%

Summary

Apache Tomcat is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2023-45648
**DESCRIPTION:**Apache Tomcat is vulnerable to HTTP request smuggling, caused by improper parsing of HTTP trailer headers. By sending a specially crafted invalid trailer header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268200 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
HMC V10.1.1010.0 V10.1.1010.0
HMC V10.2.1030.0 V10.2.1030.0
HMC V10.3.1050.0 V10.3.1050.0

Remediation/Fixes

The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/&gt;

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V10.1.1020.0 SP3 x86

|

MB04436

|

MF71508

Power HMC

|

V10.1.1020.0 SP3 ppc

|

MB04437

|

MF71509

Power HMC

|

V10.2.1040.0 SP1 x86

|

MB04429

|

MF71408

Power HMC

|

V10.2.1040.0 SP1 ppc

|

MB04430

|

MF71409

Power HMC

|

V10.3.1050.0 x86

|

MB04433

|

MF71421

Power HMC

|

V10.3.1050.0 ppc

|

MB04434

|

MF71422

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmhardware_management_consoleMatchany
VendorProductVersionCPE
ibmhardware_management_consoleanycpe:2.3:a:ibm:hardware_management_console:any:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

60.5%