Lucene search

K
ibmIBMB1E73F3E7D54C4848B67AD4137EFADC8AF5BE9A8D8699718D7BCF3F8AD566698
HistoryMay 31, 2023 - 8:28 a.m.

Security Bulletin: Vulnerabilities in Python below 3.9.16 affecting IBM Spectrum Protect Plus and its application agents for IBM Db2 and MongoDb2 using python.

2023-05-3108:28:01
www.ibm.com
13
python
ibm spectrum protect plus
ibm db2
mongodb2
cpu denial of service
cve-2022-45061
quadratic algorithm

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.008 Low

EPSS

Percentile

81.5%

Summary

CVEID: CVE-2022-45061 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16. IBM Spectrum Protect Plus and its agent for IBM Db2 and MonfoDB will use Python 3.9.16 or one of the other version with the fix.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus MongoDB Agent 10.1
IBM Spectrum Protect Plus Db2 Agent 10.1
IBM Spectrum Protect Plus MongoDB Agent 10.1

Remediation/Fixes

Upgrade to IBM Spectrum Protect Plus 10.1.14

IBM Spectrum Protect Plus Db2 Agent Affected Versions Fixing Level Platform Link to Fix and Instructions
10.1.0 - 10.1.13 10.1.14 Linux <https://www.ibm.com/support/pages/node/6942717&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_protect_plusMatch10.1
CPENameOperatorVersion
ibm spectrum protect pluseq10.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.008 Low

EPSS

Percentile

81.5%