CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
38.0%
A security vulnerability has been disclosed in the Expat library libexpat, which is installed as part of IBM Tivoli Network Manager. Information about this vulnerability has been published in a security bulletin.
CVEID:CVE-2023-52425
**DESCRIPTION:**libexpat is vulnerable to a denial of service, caused by improper system resource allocation. By sending a specially crafted request using an overly large token, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/281438 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID:CVE-2023-52426
**DESCRIPTION:**libexpat is vulnerable to a denial of service, caused by an XML entity expansion flaw if XML_DTD is undefined at compile time. By compiling specially crafted XML input, a local attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/281439 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Tivoli Network Manager | 4.2.0.0 to 4.2.0.18 |
Affected Product(s) | Version(s) | Remediation |
---|---|---|
IBM Tivoli Network Manager | 4.2.0.0 to 4.2.0.18 |
Upgrade to ITNM 4.2 Fix Pack 19 (4.2.0.19).
Download FP19 from the following locations from fixcentral.
AIX: 4.2.0-TIV-ITNMIP-AIX-FP0019
Linux: 4.2.0-TIV-ITNMIP-Linux-FP0019
zLinux:4.2.0-TIV-ITNMIP-zLinux-FP0019
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | tivoli_network_manager_ip_edition | 4.2.0 | cpe:2.3:a:ibm:tivoli_network_manager_ip_edition:4.2.0:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
38.0%