Lucene search

K
ibmIBM47EB47A21E02F3A0DFF86DA32475A47D97D7DF2CFE0CA6D3D2E69D57C3BC9FDE
HistoryMay 18, 2023 - 12:47 p.m.

Security Bulletin: Operations Dashboard is vulnerable to denial of service due to vulnerability in protobuf (CVE-2023-24535)

2023-05-1812:47:18
www.ibm.com
20
operations dashboard
denial of service
vulnerability
protobuf
cve-2023-24535
upgrade
ibm cloud pak
fix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.1%

Summary

Operations Dashboard is vulnerable to denial of service due to vulnerability in protobuf (CVE-2023-24535) with details below.

Vulnerability Details

CVEID:CVE-2023-24535
**DESCRIPTION:**Golang protobuf package is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted message consists of a minus sign, a remote attacker could exploit this vulnerability to cause a panic, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/250560 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Operations Dashboard 2021.2.1
2021.3.1
2021.4.1
2022.2.1

Remediation/Fixes

Operations Dashboard in IBM Cloud Pak for Integration
Upgrade Operations Dashboard to 2022.2.1-10-lts using the Operator upgrade process described in the IBM Documentation
<https://www.ibm.com/docs/en/cloud-paks/cp-integration/2022.2?topic=capabilities-upgrading-integration-tracing&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmarketing_operationsMatch2021.2.12021.3.12021.4.12022.2.1
VendorProductVersionCPE
ibmmarketing_operations2021.2.12021.3.12021.4.12022.2.1cpe:2.3:a:ibm:marketing_operations:2021.2.12021.3.12021.4.12022.2.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.1%

Related for 47EB47A21E02F3A0DFF86DA32475A47D97D7DF2CFE0CA6D3D2E69D57C3BC9FDE