Lucene search

K
ibmIBM86B36E7DCDA5D5A3098B7D78D21125C3804ED9250405882815F6C0A7CF14AFF8
HistorySep 26, 2023 - 3:01 p.m.

Security Bulletin: Multiple security vulnerabilities affecting Watson Knowledge Catalog for IBM Cloud Pak for Data

2023-09-2615:01:41
www.ibm.com
15
watson knowledge catalog
ibm cloud pak for data
netty
scipy
vmware tanzu spring hateoas
denial of service
outofmemoryerror
memory leak
use-after-free
security restrictions

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.7%

Summary

Multiple security vulnerabilities impacting Watson Knowledge Catalog for IBM Cloud Pak for Data. These vulnerabilities have been addressed.

Vulnerability Details

CVEID:CVE-2023-34462
**DESCRIPTION:**Netty is vulnerable to a denial of service, caused by a flaw with allocating up to 16MB of heap for each channel during the TLS handshake the SniHandler class. By sending a specially crafted client hello packet, a remote authenticated attacker could exploit this vulnerability to cause a OutOfMemoryError and so result in a denial of service condition.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/258713 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2023-25399
**DESCRIPTION:**SciPy is vulnerable to a denial of service, caused by a memory leak flaw in the Py_FindObjects function due to new reference is not decreased. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260001 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2023-29824
**DESCRIPTION:**SciPy is vulnerable to a denial of service, caused by an use-after-free bug in function Py_FindObjects. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260015 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2023-34036
**DESCRIPTION:**VMware Tanzu Spring HATEOAS could allow a remote attacker to bypass security restrictions, caused by a flaw when using on WebFlux. By sending a specially crafted request, an attacker could exploit this vulnerability to submit malicious forwarded headers.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/261128 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Knowledge Catalog on-prem 4.x

Remediation/Fixes

Upgrade to Watson Knowledge Catalog for IBM Cloud Pak for Data 4.7.2 or hgher: <https://www.ibm.com/docs/en/cloud-paks/cp-data/4.7.x?topic=overview-whats-new&gt;

Workarounds and Mitigations

None. Watson Knowledge Catalog for IBM Cloud Pak for Data must be upgraded

Affected configurations

Vulners
Node
ibmcloud_pak_for_dataMatch4.7.2
CPENameOperatorVersion
ibm cloud pak for dataeq4.7.2

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.7%