Lucene search

K
ibmIBMA217AF627E5D4EBF003F06CF6AB74664E2C52ED55B93EEA8A8CC77E3CD183FD9
HistoryDec 13, 2023 - 8:15 p.m.

Security Bulletin: IBM DataPower Gateway potentially vulnerable to a denial of service (CVE-2023-4807)

2023-12-1320:15:16
www.ibm.com
7
ibm datapower gateway
cve-2023-4807
denial of service
openssl
vulnerability
avx512-ifma
ibm cloud
x86_64
apar
it44716.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.8%

Summary

IBM has addressed the CVE

Vulnerability Details

CVEID:CVE-2023-4807
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a state corruption flaw in the POLY1305 MAC (message authentication code) implementation, when running on newer X86_64 processors supporting the AVX512-IFMA instructions. A local authenticated attacker could exploit this vulnerability to cause an incorrect result of some application dependent calculations or a crash or in some cases gain complete control of the application process.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/265578 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 10.5 CD 10.5.1 - 10.5.2
IBM DataPower Gateway 10.0.1 10.0.1.0 - 10.0.1.15
IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.7

Remediation/Fixes

Affected product Fixed in version APAR
IBM DataPOwer Gateway 10.5CD 10.5.3 IT44716
IBM DataPower Gateway 10.5.0 10.5.0.8 IT44716
IBM DataPower Gateway 10.0.1 10.0.1.16 IT44716

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch10.0.1
OR
ibmdatapower_gatewayMatch10.5.0
OR
ibmdatapower_gatewayMatch10.5

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.8%