Lucene search

K
ibmIBM8B34C508C065AF97F46EAA301E5EB359829527D59186A7D2F9001D3F449607E4
HistoryMay 30, 2023 - 10:45 a.m.

Security Bulletin: [All] Expat - CVE-2022-43680 (Publicly disclosed vulnerability)

2023-05-3010:45:20
www.ibm.com
13
vulnerability
denial of service
libexpat
ibm tivoli network manager
itnm
fix
cve-2022-43680
use-after free
xml
download
fp17
aix
linux
zlinux

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.1%

Summary

Vulnerability (CVE-2022-43680) present in libExpat used by IBM Tivoli Network Manager (ITNM) IP Edition

Vulnerability Details

CVEID:CVE-2022-43680
**DESCRIPTION:**libexpat is vulnerable to a denial of service, caused by a use-after free created by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. A remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/238951 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ITNM 4.2 GA through to 4.2.0.16

Remediation/Fixes

IBM Strongly recommends addressing the vulnerability now.

Affected Product(s): ITNM

Version(s): 4.2 GA through to 4.2.0.16

Remediation/Fix: Download FP17 from the following locations from fixcentral.

AIX: 4.2.0-TIV-ITNMIP-AIX-FP0017

Linux: 4.2.0-TIV-ITNMIP-Linux-FP0017

zLinux: 4.2.0-TIV-ITNMIP-zLinux-FP0017

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_network_manager_ip_editionMatch4.2.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.1%