Lucene search

K
ibmIBM5DBA99F37ADEBA210E32546A3A97C5A2E04A06FCA8B506552A61A9F205B7369A
HistoryJun 29, 2023 - 1:28 p.m.

Security Bulletin: IBM Decision Optimization in IBM Cloud Pak for Data is vulnerable to OpenSSL denial of service (Cryptography package)

2023-06-2913:28:12
www.ibm.com
21
ibm cloud pak for data
decision optimization
openssl vulnerability

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.003

Percentile

71.8%

Summary

There is a potential OpenSSL denial of service vulnerability in IBM Decision Optimization in IBM Cloud Pak for Data. IBM Decision Optimization in IBM Cloud Pak for Data has addressed the vulnerability.

Vulnerability Details

CVEID:CVE-2023-0286
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a type confusion error related to X.400 address processing inside an X.509 GeneralName. By passing arbitrary pointers to a memcmp call, a remote attacker could exploit this vulnerability to read memory contents or cause a denial of service.
CVSS Base score: 8.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/246611 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Decision Optimization for Cloud Pak for Data All

Remediation/Fixes

IBM strongly suggests to upgrade to IBM Decision Optimization in IBM Cloud Pak for Data 4.7 or higher, using the Operator upgrade process described in the IBM Documentation:
<https://www.ibm.com/docs/en/cloud-paks/cp-data/4.7.x?topic=upgrading-from-cloud-pak-data-version-46&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_dataMatchany
VendorProductVersionCPE
ibmcloud_pak_for_dataanycpe:2.3:a:ibm:cloud_pak_for_data:any:*:*:*:*:*:*:*

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.003

Percentile

71.8%