Lucene search

K
ibmIBM9EDECDE2B1A749007EBB011617CC7483B85FED364C2E4E05B747C280CA6207E3
HistoryJun 28, 2023 - 4:40 p.m.

Security Bulletin: Multiple vulnerabilities may affect IBM® Semeru Runtime

2023-06-2816:40:50
www.ibm.com
44
ibm semeru runtime
java se
openssl
vulnerabilities
upgrading
ibm support
x-force
cve-2023-21835
cve-2023-21830
cve-2023-21843
cve-2022-4304

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%

Summary

This bulletin covers all applicable Java SE CVEs published by OpenJDK as part of their January 2023 Vulnerability Advisory, plus CVE-2022-4304. For more information please refer to OpenJDK’s January 2023 Vulnerability Advisory and the X-Force database entries referenced below.

Vulnerability Details

CVEID:CVE-2023-21835
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow a remote authenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/245039 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2023-21830
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Serialization component could allow a remote attacker to cause a denial of service resulting in a low integrity impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/245038 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2023-21843
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Sound component could allow a remote attacker to cause a denial of service resulting in a low integrity impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/245037 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2022-4304
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/246612 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s)|**Version(s)
**
—|—
IBM Semeru Runtime| 8.0.302.0 - 8.0.352.0
IBM Semeru Runtime| 11.0.12.0 - 11.0.17.0
IBM Semeru Runtime| 17.0.1.0 - 17.0.5.0

Note: CVE-2022-4304 is applicable on Windows and Mac OS only.

Remediation/Fixes

IBM Semeru Runtime 8.0.362.0
IBM Semeru Runtime 11.0.18.0
IBM Semeru Runtime 17.0.6.0

IBM Semeru Runtime releases can be downloaded from the IBM Semeru Developer Center.

IBM customers requiring an update for an SDK shipped with an IBM product should contact IBM support, and/or refer to the appropriate product security bulletin.

APAR numbers are as follows:

IJ45270 (CVE-2023-21835)
IX90193 (CVE-2023-21830)
IJ45272 (CVE-2023-21843)
IJ45400 (CVE-2022-4304)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmsemeru_runtimeRange8.0.302.0
OR
ibmsemeru_runtimeRange8.0.352.0
OR
ibmsemeru_runtimeRange11.0.12.0
OR
ibmsemeru_runtimeRange11.0.17.0
OR
ibmsemeru_runtimeRange17.0.1.0
OR
ibmsemeru_runtimeRange17.0.5.0

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.4%