Lucene search

K
ibmIBM7C54E4F832919FB85BA22DEA5BD313C93AF51C13FF0507767FA9B896D8C8C03F
HistoryJan 16, 2024 - 7:00 a.m.

Security Bulletin: [All] Apache Tomcat (core only) - CVE-2023-42795 (Publicly disclosed vulnerability)

2024-01-1607:00:03
www.ibm.com
12
apache tomcat
power hmc
vulnerability
information leakage
ibm fix central

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.5%

Summary

Apache Tomcat is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2023-42795
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by an incomplete Cleanup vulnerability when recycling various internal objects. By skipping some parts of the recycling process, an attacker could exploit this vulnerability to obtain sensitive information leaking from the current request/response to the next.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268201 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
HMC V10.1.1010.0 V10.1.1010.0
HMC V10.2.1030.0 V10.2.1030.0
HMC V10.3.1050.0 V10.3.1050.0

Remediation/Fixes

The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/&gt;

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V10.1.1020.0 SP3 x86

|

MB04436

|

MF71508

Power HMC

|

V10.1.1020.0 SP3 ppc

|

MB04437

|

MF71509

Power HMC

|

V10.2.1040.0 SP1 x86

|

MB04429

|

MF71408

Power HMC

|

V10.2.1040.0 SP1 ppc

|

MB04430

|

MF71409

Power HMC

|

V10.3.1050.0 x86

|

MB04433

|

MF71421

Power HMC

|

V10.3.1050.0 ppc

|

MB04434

|

MF71422

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmhardware_management_consoleMatchany
CPENameOperatorVersion
hardware management console v10eqany

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.5%