Lucene search

K
ibmIBMB6D7C78AC5F9409962A33CDBC8F3AC7400C3DFAC28ADC5705A31282E439DB62D
HistoryMay 22, 2023 - 11:34 a.m.

Security Bulletin: A vulnerability in IBM Java SDK affects IBM Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines (CVE-2023-30441)

2023-05-2211:34:15
www.ibm.com
12
ibm tivoli monitoring
virtual environments agent
ibm java sdk
linux kernel-based virtual machines
cve-2023-30441
ibm runtime environment
java technology edition
sensitive information
cvss base score
workaround

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%

Summary

The security issue described in CVE-2023-30441 has been identified in IBM Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines

Vulnerability Details

CVEID:CVE-2023-30441
**DESCRIPTION:**IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE components could expose sensitive information using a combination of flaws and configurations.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253188 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines 7.2.8

Remediation/Fixes

Follow the IBM SDK, Java Technology Edition security bulletin, <https://www.ibm.com/support/pages/node/6985011&gt; to apply workaround.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_monitoringMatch7.2.8
VendorProductVersionCPE
ibmtivoli_monitoring7.2.8cpe:2.3:a:ibm:tivoli_monitoring:7.2.8:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%

Related for B6D7C78AC5F9409962A33CDBC8F3AC7400C3DFAC28ADC5705A31282E439DB62D