Lucene search

K
ibmIBM42F823016F580438604FFA389297906894BC45EE4629EF7586FF87B96CCE5B46
HistoryMay 08, 2024 - 4:16 a.m.

Security Bulletin: Vulnerability in IBM Java SDK and IBM Java Runtime affects Host On-Demand

2024-05-0804:16:11
www.ibm.com
16
ibm java sdk
ibm java runtime
host on-demand
vulnerability
eclipse openj9
denial of service
upgrade

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

13.2%

Summary

There is a vulnerability in IBM® SDK Java™ Technology Edition and IBM® Runtime Environment Java™ used by Host On-Demand. Host On-Demand has addressed the applicable CVE. This issue was disclosed as part of the IBM Semeru Runtime Quarterly CPU - Oct 2023 - Includes OpenJDK October 2023 CPU plus CVE-2023-4807 and CVE-2023-5676.

Vulnerability Details

CVEID:CVE-2023-5676
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a denial of service, caused by a flaw when a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause an infinite busy hang on a spinlock or a segmentation fault.
CVSS Base score: 4.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/271615 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
HOD 15.0-15.0.1

Remediation/Fixes

For Client Fix

Upgrade to fixed updated HOD version from the following location:

HOD v15.0.2

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ERational&product=ibm/Rational/IBM+Host+On-Demand&release=15.0.2&platform=All&function=all

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmclient_accessMatch15.0
OR
ibmclient_accessMatch15.0.1
VendorProductVersionCPE
ibmclient_access15.0cpe:2.3:a:ibm:client_access:15.0:*:*:*:*:*:*:*
ibmclient_access15.0.1cpe:2.3:a:ibm:client_access:15.0.1:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.2

Confidence

High

EPSS

0

Percentile

13.2%