Lucene search

K
ibmIBM48BA91CF2B2CA9B127D4A25A399C6E7B6D071691CDD9EC965487E9064F220C46
HistorySep 03, 2024 - 10:45 p.m.

Security Bulletin: IBM Workload Scheduler is affected by vulnerability found in glibc

2024-09-0322:45:33
www.ibm.com
3
ibm workload scheduler
glibc
denial of service
vulnerability
apar ij52172
fix central

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.3

Confidence

High

Summary

IBM Workload Scheduler is affected by vulnerability found in glibc that can cause Denial of Service (CVE-2024-33601).

Vulnerability Details

CVEID:CVE-2024-33601
**DESCRIPTION:**glibc is vulnerable to a denial of service, caused by a memory allocation failure when the Name Service Cache Daemon’s (nscd) netgroup cache uses the xmalloc or xrealloc functions. A local attacker could exploit this vulnerability to terminate the daemon.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/290170 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Workload Scheduler 9.5 to 9.5.0.6 Security 2023.03
IBM Workload Scheduler 10.1 to 10.1.0.4
IBM Workload Scheduler 10.2 to 10.2.1

Remediation/Fixes

APAR IJ52172 has been opened to address glibc vulnerability affecting IBM Workload Automation. The fix is included in IBM Workload Scheduler 9.5.0.7, IBM Workload Scheduler 10.1.0.5 and IBM Workload Scheduler 10.2.2, available on Fix Central.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmworkload_schedulerMatch9.5
OR
ibmworkload_schedulerMatch10.1
OR
ibmworkload_schedulerMatch10.2
VendorProductVersionCPE
ibmworkload_scheduler9.5cpe:2.3:a:ibm:workload_scheduler:9.5:*:*:*:*:*:*:*
ibmworkload_scheduler10.1cpe:2.3:a:ibm:workload_scheduler:10.1:*:*:*:*:*:*:*
ibmworkload_scheduler10.2cpe:2.3:a:ibm:workload_scheduler:10.2:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.3

Confidence

High