Lucene search

K
ibmIBM61977B915DACC479C9500C427C2AED7258BB08BE57B8BF2D7DCB1D8116EA7D5D
HistoryMar 27, 2024 - 5:25 p.m.

Security Bulletin: IBM DevOps Release 7.0.0.1 addresses multiple vulnerabilities.

2024-03-2717:25:57
www.ibm.com
19
ibm devops
release 7.0.0.1
vulnerabilities
apache tomcat
cve-2024-21733
cve-2024-24549
cve-2023-46589
cve-2024-23672
security bulletin

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%

Summary

IBM DevOps Release 7.0.0.1 addresses multiple vulnerabilities.

Vulnerability Details

CVEID:CVE-2024-21733
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by the leaking of unrelated request bodies in default error page. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/279952 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2024-24549
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service, caused by improper input validation by the HTTP/2 header. By sending specially crafted HTTP/2 requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/285497 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2023-46589
**DESCRIPTION:**Apache Tomcat is vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP trailer headers. By sending a specially crafted HTTP(S) trailer header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/272444 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

CVEID:CVE-2024-23672
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service, caused by an incomplete cleanup flaw. By sending specially crafted WebSocket connections, a remote attacker could exploit this vulnerability to increased resource consumption, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/285496 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
UCR - IBM UrbanCode Release 6.2.5 - 6.2.5.11
IBM DevOps Release 7.0.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerabilities now by upgrading to IBM DevOps Release 7.0.0.1 or above.

Affected Supporting Product(s) Remediation/Fix
UCR - IBM UrbanCode Release 6.2.5 - 6.2.5.11 Download IBM DevOps Release 7.0.0.1
IBM DevOps Release 7.0.0

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrational_build_forgeMatch7.0.0.1
CPENameOperatorVersion
rational build forgeeq7.0.0.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%