Lucene search

K
ibmIBMB81457EBBEA7CA89B7FDC25F5AA368E24E9B9BFA640CA8A418785EAABA1F9CD5
HistoryMar 15, 2024 - 1:37 p.m.

Security Bulletin: z/Transaction Processing Facility is affected by an OpenSSL vulnerability

2024-03-1513:37:53
www.ibm.com
7
z/transaction processing facility
openssl vulnerability
denial of service
pkcs12 file
remote attacker
crash
cvss base score 3.1
apar pj47251

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%

Summary

The z/TPF version of OpenSSL was updated to address the vulnerability described by CVE-2024-0727.

Vulnerability Details

CVEID:CVE-2024-0727
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by improper input validation. By persuading a victim to open a specially crafted PKCS12 file, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280532 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
z/Transaction Processing Facility 1.1

Remediation/Fixes

Product VRMF APAR Remediation/First Fix
z/TPF 1.1 PJ47251 Apply the APAR, which is available for download from the TPF Family Products: Maintenance web page.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmz\/transaction_processing_facilityMatch1.1

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%