Lucene search

K
ibmIBM9E730F76DD207F8BCF7E62ECABD4850B18E714ED92F0AAEB7ACC54B0B4E81356
HistoryFeb 01, 2023 - 9:52 p.m.

Security Bulletin: Vulnerability in Moment.js affects IBM Process Mining . CVE-2022-24785

2023-02-0121:52:34
www.ibm.com
11
moment.js
ibm process mining
cve-2022-24785
path traversal
security fixes
upgrade

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.1%

Summary

There is a vulnerability in Moment.js that could allow a path traversal. The code is used by IBM Process Mining. This bulletin identifies the security fixes to apply to address the vulnerability.

Vulnerability Details

CVEID:CVE-2022-24785
**DESCRIPTION:**Moment.js could allow a remote attacker to traverse directories on the system, caused by improper validation of user supplied input. An attacker could send a specially-crafted locale string containing β€œdot dot” sequences (/…/) to switch arbitrary moment locale.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/223451 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Process Mining 1.13.0.0

Remediation/Fixes

Remediation/Fixes guidance:

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Process Mining 1.13.0.0

Upgrade to version 1.13.1

1.Login to PassPortAdvantage

2. Search for
M083FML Process Mining 1.13.1 Server Multiplatform Multilingual

3. Download package

4. Follow install instructions

5. Repeat for M083GML Process Mining 1.13.1 Client Windows Multilingual

| |

Workarounds and Mitigations

None known

Affected configurations

Vulners
Node
ibmcloud_pak_for_automationMatch1.13.0.0
VendorProductVersionCPE
ibmcloud_pak_for_automation1.13.0.0cpe:2.3:a:ibm:cloud_pak_for_automation:1.13.0.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

71.1%