Lucene search

K
ibmIBM95F7B6FC92E5A2BE639D42F21E06102D47B1A48C558B8282D38D0B74C7A60656
HistorySep 13, 2024 - 8:04 a.m.

Security Bulletin: IBM Maximo Application Suite uses bcprov-jdk15on-1.70.jar which is vulnerable to CVE-2024-29857.

2024-09-1308:04:33
www.ibm.com
2
ibm maximo application suite
vulnerable
bouncy castle crypto package
ec certificate
denial of service
cpu consumption
cve-2024-29857
iot component
remediation
version
workarounds

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

IBM Maximo Application Suite uses bcprov-jdk15on-1.70.jar which is vulnerable to CVE-2024-29857. This bulletin contains information regarding the vulnerability and its fixture.

Vulnerability Details

CVEID:CVE-2024-29857
**DESCRIPTION:**The Bouncy Castle Crypto Package For Java is vulnerable to a denial of service, caused by improper input validation. By importing an EC certificate with crafted F2m parameters, a remote attacker could exploit this vulnerability to cause excessive CPU consumption.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/290285 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Maximo Application Suite - IoT Component 9.0
IBM Maximo Application Suite - IoT Component 8.8
IBM Maximo Application Suite - IoT Component 8.7

Remediation/Fixes

Remediated Product(s) Version(s)
IBM Maximo Application Suite - IoT Component 9.0.0
IBM Maximo Application Suite - IoT Component 8.8.8
IBM Maximo Application Suite - IoT Component 8.7.12

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch9.0
OR
ibmmaximo_application_suiteMatch8.8
OR
ibmmaximo_application_suiteMatch8.7
VendorProductVersionCPE
ibmmaximo_application_suite9.0cpe:2.3:a:ibm:maximo_application_suite:9.0:*:*:*:*:*:*:*
ibmmaximo_application_suite8.8cpe:2.3:a:ibm:maximo_application_suite:8.8:*:*:*:*:*:*:*
ibmmaximo_application_suite8.7cpe:2.3:a:ibm:maximo_application_suite:8.7:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H