Lucene search

K
ibmIBM8EBB9B22D65F20A0258015D43D6D1D8CF205717532CF10F2553C76164026D370
HistoryMay 09, 2023 - 6:16 p.m.

Security Bulletin: Setuptools is vulnerable to CVE-2022-40897 used in IBM Maximo Application Suite - Monitor Component

2023-05-0918:16:10
www.ibm.com
20
ibm maximo application suite
setuptools
cve-2022-40897
denial of service
vulnerability
fixpack 8.9.3
fixpack 8.10.0

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

77.3%

Summary

IBM Maximo Application Suite - Monitor Component uses setuptools which is vulnerable to CVE-2022-40897.

Vulnerability Details

CVEID:CVE-2022-40897
**DESCRIPTION:**Pypa Setuptools is vulnerable to a denial of service, caused by improper input validation. By sending request with a specially crafted regular expression, an remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/243028 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Maximo Application Suite - Monitor Component 8.9.2

Remediation/Fixes

Affected Product(s) Fixpack Version(s)
IBM Maximo Application Suite - Monitor Component 8.9.3, 8.10.0, or latest (available from the Catalog under Update Available)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch8.9
VendorProductVersionCPE
ibmmaximo_application_suite8.9cpe:2.3:a:ibm:maximo_application_suite:8.9:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

77.3%