Lucene search

K
ibmIBMADBD6F6BAF0E51A4C232A897636A5E23BAA89B73F8F83D0783402B11522BD854
HistoryAug 07, 2024 - 6:27 a.m.

Security Bulletin: Multiple vulnerabilities found on thirdparty libraries used by IBM® MobileFirst Platform

2024-08-0706:27:43
www.ibm.com
7
ibm mobilefirst foundation
vulnerabilities
third party libraries
phishing attacks
fix
ifix build

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

26.6%

Summary

There are multiple vulnerabilities in open source libraries used by IBM MobileFirst Platform Foundation. They are addressed in this update.

Vulnerability Details

CVEID:CVE-2024-22243
**DESCRIPTION:**VMware Tanzu Spring Framework could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability when using UriComponentsBuilder to parse an externally provided URL. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/283965 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)

CVEID:CVE-2024-22259
**DESCRIPTION:**VMware Tanzu Spring Framework could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in UriComponentsBuilder. An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/285631 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MobileFirst Foundation 8.x.x

Remediation/Fixes

Product(s) Version Number(s) and/or range Remediation/Fix/Instructions
IBM MobileFirst Platform Foundation 8.0.0.0 iFix build 8.0.0.0-MFPF-IF202404220901 build includes fixes to resolve vulnerable third party libraries.

Please download from FixCentral

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmobilefirst_platform_foundationMatch8.0.0
VendorProductVersionCPE
ibmmobilefirst_platform_foundation8.0.0cpe:2.3:a:ibm:mobilefirst_platform_foundation:8.0.0:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

26.6%