Lucene search

K
ibmIBMA9C2ADE0DA9BCA679F7A7807F901DBB80FA9C445A05E4303D1AF991B29005FF5
HistoryJan 02, 2024 - 6:04 p.m.

Security Bulletin: Multiple vulnerabilities affect IBM Db2® REST

2024-01-0218:04:04
www.ibm.com
22
ibm db2 rest
multiple vulnerabilities
fixed
update
golang go
execution
arbitrary code
system
enforcement
line directive
cvss base score
cvss temporal score
affected products
versions
ibm cloud
container registry

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.002

Percentile

57.2%

Summary

IBM has released the below fix for IBM Db2® REST in response to multiple vulnerabilities found in multiple components. The vulnerabilities have been addressed.

Vulnerability Details

CVEID:CVE-2023-39323
**DESCRIPTION:**Golang Go could allow a remote attacker to execute arbitrary code on the system, caused by improper enforcement of line directive restrictions in the “//go:cgo_” directives. By providing specially crafted input in the linker and compiler flags, an attacker could exploit this vulnerability to execute arbitrary code on the system. Note: The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268524 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Db2 Rest

1.0.0.121-amd64 to 1.0.0.291-amd64

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading to the latest IBM® Db2® REST release containing the fix for these issues.

Product(s) Fixed in Version(s)
Db2 REST

1.0.0.1158-amd64

latest-amd64

Follow the instructions below to download IBM Db2 REST from the IBM Cloud Container Registry.

<https://www.ibm.com/docs/en/db2/11.5?topic=endpoints-downloading-rest-service&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdb2_for_linux\,_unix_and_windowsMatch11.5.8.0
VendorProductVersionCPE
ibmdb2_for_linux\,_unix_and_windows11.5.8.0cpe:2.3:a:ibm:db2_for_linux\,_unix_and_windows:11.5.8.0:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.002

Percentile

57.2%