Lucene search

K
ibmIBM50E1F6A909D483A6A1F4E4A73C8843379E6D35C68D91CC134F25CE2AAF633DDC
HistoryOct 10, 2023 - 12:43 p.m.

Security Bulletin: Due to the use of XStream, IBM Tivoli Netcool Configuration Manager is vulnerable to Denial of Service (DoS) attacks

2023-10-1012:43:57
www.ibm.com
12
ibm tivoli netcool configuration manager
dos vulnerability
xstream serialization
cve-2022-41966
itncm 6.4.2
fix pack 19

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

0.01 Low

EPSS

Percentile

83.8%

Summary

XStream is used in ITNCM to serialize XML data and may be vulnerable to Denial of Service attacks (DoS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by causing a stackoverflow. This effect may support a denial of service attack (CVE-2022-41966) .

Vulnerability Details

CVEID:CVE-2022-41966
**DESCRIPTION:**XStream is vulnerable to a denial of service, caused by a stack-based buffer overflow. By manipulating the processed input stream at unmarshalling time, a remote attacker could exploit this vulnerability to replace or inject objects and cause a denial of service.
CVSS Base score: 8.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/243448 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ITNCM 6.4.2

Remediation/Fixes

Affected Product(s) Version(s) Remediation
ITNCM 6.4.2 Upgrade to ITNCM 6.4.2 Fix Pack 19 (6.4.2.19)

ITNCM 6.4.2 Fix Pack 19 can be downloaded from Fix Central: 6.4.2-TIV-ITNCM-FP019

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_netcool_security_managerMatch6.4.2

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

0.01 Low

EPSS

Percentile

83.8%