Lucene search

K
ibmIBM6EB6D12333E4617644885864954279AB5CA36566C777B3D6389B60E7BE7ECC04
HistoryMar 27, 2024 - 5:19 p.m.

Security Bulletin: IBM DevOps Build 7.0.0.1 addresses multiple vulnerabilities.

2024-03-2717:19:49
www.ibm.com
11
ibm devops build 7.0.0.1
apache tomcat
multiple vulnerabilities
remote attackers
sensitive information
denial of service
xss attacks
upgrade

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%

Summary

IBM DevOps Build 7.0.0.1 addresses multiple vulnerabilities.

Vulnerability Details

CVEID:CVE-2024-21733
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by the leaking of unrelated request bodies in default error page. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/279952 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2023-46589
**DESCRIPTION:**Apache Tomcat is vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP trailer headers. By sending a specially crafted HTTP(S) trailer header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/272444 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

CVEID:CVE-2024-23672
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service, caused by an incomplete cleanup flaw. By sending specially crafted WebSocket connections, a remote attacker could exploit this vulnerability to increased resource consumption, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/285496 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2024-24549
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service, caused by improper input validation by the HTTP/2 header. By sending specially crafted HTTP/2 requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/285497 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
UCB - IBM UrbanCode Build 6.1.7 - 6.1.7.10
IBM DevOps Build 7.0.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerabilities now by upgrading to IBM DevOps Build 7.0.0.1 or above.

Affected Supporting Product(s) Remediation/Fix
UCB - IBM UrbanCode Build 6.1.7 - 6.1.7.10 Download IBM DevOps Build 7.0.0.1
IBM DevOps Build 7.0.0

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrational_build_forgeMatch7.0.0.1
CPENameOperatorVersion
rational build forgeeq7.0.0.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%