Lucene search

K
ibmIBMA63EAE8C9C9A08C14DCEDB3C5F9D3581C3F9B99717B1987A635624000447349C
HistoryFeb 14, 2024 - 2:30 p.m.

Security Bulletin: IBM Datapower Operations Dashboard is vulnerable to execute arbitrary code on the system [CVE-2023-46604]

2024-02-1414:30:11
www.ibm.com
13
ibm
datapower operations dashboard
apache activemq
vulnerable
execute arbitrary code
cve-2023-46604
security bulletin
upgrade
version 1.0.20.0
ibm support

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

7.9 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%

Summary

Apache ActiveMQ is used by the IBM Datapower Operations Dashboard in its messaging infrastructure. This bulletin identifies the steps to take to address the vulnerability.

Vulnerability Details

CVEID:CVE-2023-46604
**DESCRIPTION:**Apache ActiveMQ and ActiveMQ Legacy OpenWire Module could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the class types in the OpenWire protocol. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/269795 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
DataPower Operations Dashboard 1.0.19.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading to version 1.0.20.0
https://www.ibm.com/support/fixcentral/swg/selectFixes?fixids=DPOD-1.0.20.0&product=ibm%2FWebSphere%2FWebSphere%20DataPower%20SOA%20Appliances&source=dbluesearch&mhsrc=ibmsearch_a&mhq=dpod&function=fixId&parent=ibm/WebSphere

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch1.0

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

7.9 High

AI Score

Confidence

High

0.964 High

EPSS

Percentile

99.6%