Lucene search

K
ibmIBM7C06E84BC3B0A093B18185373492AA75C23D1EBD79B6590456C033E77898D674
HistoryNov 28, 2023 - 11:19 p.m.

Security Bulletin: IBM InfoSphere Information Server is vulnerable to cross-site request forgery (CVE-2023-38268)

2023-11-2823:19:58
www.ibm.com
8
ibm infosphere infoserver
cross-site request forgery
vulnerability
patch
websphere
samesiteε±žζ€§
jsessionid
ltpatoken2

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

Summary

A cross-site request forgery vulnerability in IBM InfoSphere Information Server was addressed.

Vulnerability Details

CVEID:CVE-2023-38268
**DESCRIPTION:**IBM InfoSphere Information Server is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260585 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Information Server 11.7

Remediation/Fixes

Product VRMF APAR Remediation
InfoSphere Information Server, InfoSphere Information Server on Cloud 11.7 DT223616 --Apply IBM InfoSphere Information Server version 11.7.1.0
--Apply InfoSphere Information Server version 11.7.1.4
--Apply InfoSphere Information Server 11.7.1.4 Service pack 2

Note:

Samesite can be configured as strict for two WebSphere related cookies.

1. JSESSIONID cookie: the β€˜CookieSameSite’ property can be specified as β€˜Strict’ in the WebSphere Administration console at Servers > Server Types > WebSphere application servers > server1 > Session management > Custom properties > New. See details in PH22157.

2. LtpaToken2 cookie: in the WebSphere Administration console, a new custom property com.ibm.websphere.security.addSameSiteAttributeToCookie can be added at Security > Global security > Custom properties > New. See details in WebSphere documentation.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibminfosphere_information_serverMatch11.7

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.8%

Related for 7C06E84BC3B0A093B18185373492AA75C23D1EBD79B6590456C033E77898D674