Lucene search

K
ibmIBM7C1F37066326C7A75E49C7E9AD2E78DBFEAA12C96F5FC5CE469DECF3115BBAB4
HistoryJan 12, 2024 - 6:00 a.m.

Security Bulletin: The IBM® Engineering Lifecycle Engineering products using IBM SDK, Java Technology Edition Quarterly CPU - Oct 2023 - Includes Oracle October 2023 CPU plus are vulnerable to CVE-2023-5676

2024-01-1206:00:04
www.ibm.com
16
ibm
engineering lifecycle engineering
sdk
java technology edition
quarterly cpu
oct 2023
vulnerability
cve-2023-5676
websphere
application server
liberty
jazz foundation
test management
workflow management
requirements management doors next
reporting service
lifecycle optimization
elm installer
engineering insights
global configuration management
common licensing
security bulletin
remediation
fixes
update

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.2%

Summary

There are multiple vulnerabilities in the IBM® SDK, Java™ Technology Edition that is shipped with IBM WebSphere Application Server and IBM WebSphere Application Server Liberty. Following IBM® Engineering Lifecycle Engineering products are vulnerable to this attack, it has been addressed in this bulletin: Jazz Foundation, IBM Engineering Test Management, IBM Engineering Workflow Management, IBM Engineering Requirements Management DOORS Next, IBM Jazz Reporting Service, IBM Engineering Lifecycle Optimization - Publishing, ELM Installer, IBM Engineering Lifecycle Optimization - Engineering Insights, Global Configuration Management, IBM Common Licensing

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Jazz Reporting Service 7.0.3
IBM Engineering Lifecycle Optimization - Publishing
Jazz Foundation
Global Configuration Management
IBM Engineering Workflow Management
IBM Engineering Requirements Management DOORS Next
ELM Installer
IBM Engineering Test Management
IBM Engineering Lifecycle Optimization - Engineering Insights
IBM Engineering Test Management
IBM Jazz Reporting Service 7.0.2
IBM Engineering Lifecycle Optimization - Publishing
Jazz Foundation
Global Configuration Management
IBM Engineering Workflow Management
IBM Engineering Requirements Management DOORS Next
ELM Installer
IBM Engineering Test Management
IBM Engineering Lifecycle Optimization - Engineering Insights
IBM Engineering Test Management
IBM Common Licensing Agent 9.0, ART 9.0

Remediation/Fixes

CVE-2023-5676 may affect IBM® Engineering Lifecycle Engineering products mentioned above.

If any of the mentioned affected product is deployed on one of the above versions, Please follow the instruction given in the following article.

Link: <https://www.ibm.com/support/pages/node/7078745&gt;

How to update the IBM SDK for Java of Engineering Lifecycle Management products? Please refer below article for more details.

<https://www.ibm.com/support/pages/how-update-ibm-sdk-java-engineering-lifecycle-management-products&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_engineering_lifecycle_management_baseMatch7.0.2
OR
ibmibm_engineering_lifecycle_management_baseMatch7.0.3
OR
ibmibm_engineering_lifecycle_management_baseMatch9.0
OR
ibmibm_engineering_lifecycle_management_baseMatch9.0

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.2%

Related for 7C1F37066326C7A75E49C7E9AD2E78DBFEAA12C96F5FC5CE469DECF3115BBAB4