Lucene search

K
ibmIBM8EA1C7F967DB84B2496182E29AD373587CCD58C81F3C6D2A05D122AC74FF197C
HistoryJul 05, 2023 - 8:42 p.m.

Security Bulletin: IBM Watson CP4D Data Stores is vulnerable to a denial of service ( CVE-2023-27540)

2023-07-0520:42:36
www.ibm.com
9
ibm watson cp4d data stores
denial of service
vulnerability
cve-2023-27540
upgrade
ibm cloud pak for data
ibm cloud pak for data version 4.7.0

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.8%

Summary

Potential denial of service vulnerability in IBM Watson CP4D Data Stores (CVE-2023-27540) has been identified that may affect IBM Watson CP4D Data Stores Refer to details for additional information.

Vulnerability Details

CVEID:CVE-2023-27540
**DESCRIPTION:**IBM Watson CP4D Data Stores does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/248924 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Watson CP4D Data Stores All

Remediation/Fixes

For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest (v4.7.0 or later releases) release of IBM Watson Assistant for IBM Cloud Pak for Data which maintains backward compatibility with the versions listed above.

Product Latest Version Remediation/Fix/Instructions
IBM Cloud Pak for Data Version 4.7.0

Follow instructions for Installing Watson Assistant in Link to Release (v4.7.0 release information)

<https://www.ibm.com/docs/en/cloud-paks/cp-data/4.7.x&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwatson_cp4d_data_storesMatchany
VendorProductVersionCPE
ibmwatson_cp4d_data_storesanycpe:2.3:a:ibm:watson_cp4d_data_stores:any:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

35.8%

Related for 8EA1C7F967DB84B2496182E29AD373587CCD58C81F3C6D2A05D122AC74FF197C