Lucene search

K
ibmIBM7636CB64487877AE4DE66CFFC3192B5D51A4300677B6FC5A80C97B703155DF5C
HistoryJan 03, 2024 - 6:20 p.m.

Security Bulletin: Vulnerability in Golang Go affects IBM Cloud Pak System.

2024-01-0318:20:47
www.ibm.com
12
vulnerability
golang go
ibm cloud pak system
denial of service
tls handshake
remote attacker
cve-2022-41724
cvss 6.5
ibm cloud pak system 2.3.3.0
ibm cloud pak system software suite
upgrade
interim fix
power
intel

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.0%

Summary

Vulnerability in Golang Go affects IBM Cloud Pak System[CVE-2022-41724].

Vulnerability Details

CVEID:CVE-2022-41724
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw when processing large TLS handshake records. By sending specially-crafted TLS handshake records, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/248257 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak System 2.3.3.0 - 2.3.3.6 (Intel)
IBM Cloud Pak System Software Suite 2.3.3.0, 2.3.3.6 (Intel)
IBM Cloud Pak System Software Suite 2.3.1.1, 2.3.2.0 (Power)

Remediation/Fixes

For unsupported versions the recommendation is to upgrade to supported version of the product.

This security bulletin applies to Cloud Pak System, Cloud Pak System Software, Cloud Pak System Software Suite.

For IBM Cloud Pak System v2.3.3.0, v.2.3.3.1, v.2.3.3.2, v.2.3.3.3, v2.3.3.3 iFix 1, v2.3.3.4, v2.3.3.5 for Intel
Upgrade to IBM Cloud Pak System v2.3.3.6 and apply IBM Cloud Pak System v2.3.3.6 Interim Fix 1 at Fix Central.
Information on upgrading here <https://www.ibm.com/support/pages/node/6959035&gt;

For IBM Cloud Pak System V2.3.3.6,
Apply Cloud Pak System V2.3.3.6 Interim Fix 1 at Fix Central
Information on upgrading available at <https://www.ibm.com/support/pages/node/7017280&gt;

For Cloud Pak System V2.3.0.1, V2.3.1.1, V2.3.2.0, for Power
Upgrade to Cloud Pak System v2.3.3.7
Information on upgrading here https://www.ibm.com/support/pages/node/6982511

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_systemMatch2.3
CPENameOperatorVersion
ibm cloud pak system softwareeq2.3

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.0%