Lucene search

K
ibmIBMA9FC9C40DBE45E88C0BE9A34D5BE3FE3AEDA067A0CFC7A091ED3AAF4B026361D
HistoryJan 30, 2023 - 5:50 p.m.

Security Bulletin: IBM Workload Scheduler potentially affected by parsing issue with binary data in protobuf-java core (CVE-2022-3171)

2023-01-3017:50:56
www.ibm.com
17
ibm workload scheduler
parsing issue
protobuf-java core
denial of service
vulnerability
garbage collection
apar ij44025

0.001 Low

EPSS

Percentile

32.6%

Summary

A parsing issue with binary data in protobuf-java core can lead to a denial of service attack and potentially affects IBM Workload Scheduler 9.5 and IBM Workload Scheduler 10.1

Vulnerability Details

CVEID:CVE-2022-3171
**DESCRIPTION:**protobuf-java core and lite are vulnerable to a denial of service, caused by a flaw in the parsing procedure for binary and text format data. By sending non-repeated embedded messages with repeated or unknown fields, a remote authenticated attacker could exploit this vulnerability to cause long garbage collection pauses.
CVSS Base score: 5.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/238394 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Workload Scheduler 9.5
IBM Workload Scheduler 10.1

Remediation/Fixes

APAR IJ44025 has been opened to address protobuf-java core vulnerability affecting IBM Workload Scheduler.
APAR IJ44025 is included in IBM Workload Scheduler 9.5.0.6 Security Update and in IBM Workload Scheduler 10.1.0.1, both available on FixCentral.

Workarounds and Mitigations

None

CPENameOperatorVersion
eq9.5