Lucene search

K
ibmIBMA30BDBF033F335771F1EBBD86A4D24BEBC8530EE89CAF81A4C89057E9527E538
HistoryJun 13, 2023 - 1:08 p.m.

Security Bulletin: IBM Workload Scheduler is potentially affected by a vulnerability in OpenSSL causing system crash (CVE-2022-4450)

2023-06-1313:08:57
www.ibm.com
10
ibm workload scheduler
vulnerability
openssl
cve-2022-4450
system crash
apar ij47125

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

47.0%

Summary

IBM Workload Scheduler is potentially affected by a vulnerability in OpenSSL that could cause a system crash

Vulnerability Details

CVEID:CVE-2022-4450
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a double-free error related to the improper handling of specific PEM data by the PEM_read_bio_ex() function. By sending specially crafted PEM files for parsing, a remote attacker could exploit this vulnerability to cause the system to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/246615 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Workload Scheduler 9.5
IBM Workload Scheduler 9.4
IBM Workload Scheduler 10.1

Remediation/Fixes

APAR IJ47125 has been opened to address the OpenSSL vulnerability for IBM Workload Scheduler.
APAR IJ47125 has been included in 9.5.0.6 Security 2023.03 and 10.1.0.3 versions. Customers using IBM Workload Scheduler 9.4 should open a support ticket requesting a fix to apply on top of 9.4.0.7 version.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmworkload_schedulerMatch9.4
OR
ibmworkload_schedulerMatch9.5

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

47.0%