Lucene search

K
ibmIBMB768855E8C738A5B00457C5D1B9A9B414C5E89F585C189FD0169729EDDC79CAD
HistoryAug 30, 2022 - 6:16 p.m.

Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to Netty information disclosure (CVE-2022-24823)

2022-08-3018:16:54
www.ibm.com
12
ibm watson assistant
ibm cloud pak for data
netty information disclosure
cve-2022-24823
upgrade
v4.0.8
security bulletin

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.4%

Summary

Potential vulnerabilities in Netty - CVE-2022-24823 has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Refer to details for additional information.

Vulnerability Details

CVEID:CVE-2022-24823
**DESCRIPTION:**Netty could allow a local authenticated attacker to obtain sensitive information, caused by a flaw when temporary storing uploads on the disk is enabled. By gaining access to the local system temporary directory, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/225922 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Products and Versions:

Affected Product(s) Version(s)
Watson Assistant for IBM Cloud Pak for data 1.5.0, 4.0.0, 4.0.2, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8

Remediation/Fixes

For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest (v4.0.8) release of IBM Watson Assistant for IBM Cloud Pak for Data which maintains backward compatibility with the versions listed above.

Product Latest Version Remediation/Fix/Instructions
IBM Watson Assistant for IBM Cloud Pak for Data 4.5.1

Follow instructions for Installing Watson Assistant in Link to Release (v4.5.1 release information)

<https://www.ibm.com/docs/en/cloud-paks/cp-data/4.0?topic=assistant-installing-watson&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwatson_developer_cloudMatch1.5.0
OR
ibmwatson_developer_cloudMatch4.0.0
OR
ibmwatson_developer_cloudMatch4.0.2
OR
ibmwatson_developer_cloudMatch4.0.4
OR
ibmwatson_developer_cloudMatch4.0.5
OR
ibmwatson_developer_cloudMatch4.0.6
OR
ibmwatson_developer_cloudMatch4.0.7
OR
ibmwatson_developer_cloudMatch4.0.8
VendorProductVersionCPE
ibmwatson_developer_cloud1.5.0cpe:2.3:a:ibm:watson_developer_cloud:1.5.0:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.0cpe:2.3:a:ibm:watson_developer_cloud:4.0.0:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.2cpe:2.3:a:ibm:watson_developer_cloud:4.0.2:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.4cpe:2.3:a:ibm:watson_developer_cloud:4.0.4:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.5cpe:2.3:a:ibm:watson_developer_cloud:4.0.5:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.6cpe:2.3:a:ibm:watson_developer_cloud:4.0.6:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.7cpe:2.3:a:ibm:watson_developer_cloud:4.0.7:*:*:*:*:*:*:*
ibmwatson_developer_cloud4.0.8cpe:2.3:a:ibm:watson_developer_cloud:4.0.8:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.4%