Lucene search

K
ibmIBM4FA49396E8AC7A92E371A648A0D92F7A454976AB94672EFF104FDF5428E4E027
HistoryDec 14, 2023 - 8:55 p.m.

Security Bulletin: Vulnerability with MariaDB and OpenJDK affect IBM Cloud Object Storage Systems (Dec2023v1)

2023-12-1420:55:29
www.ibm.com
17
mariadb
openjdk
ibm cloud object storage
clevos
denial of service
java se
oracle
graalvm
hotspot

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

57.2%

Summary

Vulnerability with MariaDB - (CVE-2022-47015 ) and OpenJDK (CVE-2023-22081 & CVE-2023-22025) This vulnerability have been addressed in the latest ClevOS releases

Vulnerability Details

CVEID:CVE-2022-47015
**DESCRIPTION:**MariaDB is vulnerable to a denial of service, caused by a NULL pointer dereference in function spider_db_mbase::print_warnings. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/245212 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2023-22081
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow a remote attacker to cause no confidentiality impact, no integrity impact, and low availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268929 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2023-22025
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK related to the Hotspot component could allow a remote attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268930 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Object System 3.17.0.128 or Prior Releases

Remediation/Fixes

Product(s) Version Number Remediation/Fix
IBM Cloud Object System 3.17.0.131 https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Cloud+Object+Storage+System&release=3.17.0.131&platform=All&function=all
IBM Cloud Object System 3.18.0.21 https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Cloud+Object+Storage+System&release=3.18.0.21&platform=All&function=all

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_object_storage_systemMatch3.17
OR
ibmcloud_object_storage_systemMatch3.18
VendorProductVersionCPE
ibmcloud_object_storage_system3.17cpe:2.3:a:ibm:cloud_object_storage_system:3.17:*:*:*:*:*:*:*
ibmcloud_object_storage_system3.18cpe:2.3:a:ibm:cloud_object_storage_system:3.18:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

57.2%