Lucene search

K
ibmIBM7EF70E8A323CCCA40FEC4034D4017D872AC632029EC97CDDB02C9000B5D193C7
HistoryJul 25, 2022 - 10:59 a.m.

Security Bulletin: IBM Sterling Partner Engagement Manager is vulnerable to Slowloris HTTP DOS attack (CVE-2022-35639)

2022-07-2510:59:09
www.ibm.com
30
ibm sterling partner engagement manager
slowloris attack
denial-of-service
vulnerability
unresponsive server
cve-2022-35639
threaded web servers
ibm sterling pem
version 6.1
version 6.2
version 22.2
remediation
fix
cloud
saas

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.4%

Summary

IBM Sterling Partner Engagement Manager is vulnerable to Slowloris attack is a type of denial-of-service (DoS) attack which targets threaded web servers. The issue has been addressed.

Vulnerability Details

CVEID:CVE-2022-35639
**DESCRIPTION:**IBM Sterling Partner Engagement Manager do not limit the length of a connection which could cause the server to become unresponsive.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/230932 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Sterling Partner Engagement Manager Standard Edition 6.1
IBM Sterling Partner Engagement Manager Standard Edition 6.2
IBM Sterling Partner Engagement Manager on Cloud / SaaS 22.2

Remediation/Fixes

Product Version Remediation / Link
IBM Sterling Partner Engagement Manager Standard Edition 6.1 6.1.2.5 / http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&fixids=IBM_PEM_Standard_6.1.2.5&source=SAR
IBM Sterling Partner Engagement Manager Standard Edition 6.2 6.2.0.3 / http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FIBM+Sterling+Partner+Engagement+Manager+Software&fixids=IBM_PEM_Standard_6.2.0.3&source=SAR
IBM Sterling Partner Engagement Manager on Cloud / SaaS 22.2 22.2.1 / us.icr.io/gold/pem:22.2.1

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmpartner_engagement_managerMatch6.1
VendorProductVersionCPE
ibmpartner_engagement_manager6.1cpe:2.3:a:ibm:partner_engagement_manager:6.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.4%

Related for 7EF70E8A323CCCA40FEC4034D4017D872AC632029EC97CDDB02C9000B5D193C7