Lucene search

K
ibmIBM68258993F0A4E659CE5BD9A93951A5938DDCA5AA2BAB7B3394297245B42DF89B
HistoryOct 20, 2023 - 2:11 p.m.

Security Bulletin: IBM App Connect Enterprise Toolkit and IBM Integration Bus Toolkit are vulnerable to a denial of service due to Okio GzipSource (CVE-2023-3635).

2023-10-2014:11:06
www.ibm.com
28
ibm
app connect enterprise
integration bus
denial of service
okio gzipsource
cve-2023-3635
vulnerability
apar
it44486

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.3%

Summary

IBM App Connect Enterprise Toolkit and IBM Integration Bus Toolkit using Maven projects feature are vulnerable to a denial of service due to Okio GzipSource.

Vulnerability Details

CVEID:CVE-2023-3635
**DESCRIPTION:**Okio GzipSource is vulnerable to a denial of service, caused by unhandled exception. By sending a specially crafted gzip buffer, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260866 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.10.0
IBM App Connect Enterprise 11.0.0.1 - 11.0.0.23
IBM Integration Bus 10.1 - 10.1.0.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Toolkit and****IBM Integration Bus Toolkit

Affected Product(s) Version(s) APAR Remediation / Fix
IBM App Connect Enterprise 12.0.1.0 - 12.0.10.0 IT44486

Interim fix for APAR (IT44486) is available to apply to 12.0.10.0 from

IBM Fix Central

IBM App Connect Enterprise| 11.0.0.1 - 11.0.0.23| IT44486|

Interim fix for APAR (IT44486) is available to apply to 11.0.0.23 from

IBM Fix Central

IBM Integration Bus| 10.1 - 10.1.0.1| IT44486|

APAR (IT44486) is available from

IBM Integration Bus 10.1 - Fix pack 10.1.0.2

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.10.0
OR
ibmapp_connect_enterpriseRange11.0.0.1
OR
ibmapp_connect_enterpriseRange11.0.0.23
OR
ibmintegration_busRange10.1
OR
ibmintegration_busRange10.1.0.1
VendorProductVersionCPE
ibmapp_connect_enterprise*cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
ibmintegration_bus*cpe:2.3:a:ibm:integration_bus:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.3%