Lucene search

K
ibmIBM79593CB8F537748D379DBC67EADE67BE463915F19846BB44C600DCCB16387ADF
HistoryDec 13, 2022 - 3:58 p.m.

Security Bulletin: Vulnerability in OAuthlib affects IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift (CVE-2022-36087)

2022-12-1315:58:20
www.ibm.com
21
oauthlib
ibm spectrum protect plus
container backup
kubernetes
openshift
vulnerability
cve-2022-36087
denial of service

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.0%

Summary

Denial of service vulnerability in OAuthlib may affect IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift.

Vulnerability Details

CVEID:CVE-2022-36087
**DESCRIPTION:**OAuthlib is vulnerable to a denial of service, caused by improper input validation. By sending a specially-crafted request using IPV6 URI, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/235780 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes 10.1.5-10.1.12
IBM Spectrum Protect Plus Container Backup and Restore for Red Hat OpenShift 10.1.7-10.1.12

Remediation/Fixes

IBM Spectrum Protect Plus Affected Versions|Fixing Level|Platform|**Link to Fix and Instructions
**
—|—|—|—
10.1.5-10.1.12 (Kubernetes)
10.1.7-10.1.12 (Red Hat OpenShift)| 10.1.12.3| Linux| <https://www.ibm.com/support/pages/node/6603663&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_protect_plusMatch10.1
VendorProductVersionCPE
ibmspectrum_protect_plus10.1cpe:2.3:a:ibm:spectrum_protect_plus:10.1:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.0%