Lucene search

K
ibmIBMBCD2ADA3AAA5CF3D7B396B598EFD996FED46E22A1F9B1783492E55A835100F32
HistoryFeb 14, 2024 - 12:00 p.m.

Security Bulletin: Multiple vulnerabilities affect IBM® SDK, Java™ Technology Edition for Content Collector for Email, Content Collector for File Systems and Content Collector for Microsoft SharePoint

2024-02-1412:00:07
www.ibm.com
10
ibm sdk
java technology edition
content collector
email
file systems
microsoft sharepoint
vulnerabilities
remote attackers
confidentiality impact
integrity impact
availability impact
version 4.0.1
interim fix if009

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.8%

Summary

CVE-2023-22081 and CVE-2023-22067 were disclosed in the Oracle October 2023 Critical Patch Update.

Vulnerability Details

CVEID:CVE-2023-22081
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow a remote attacker to cause no confidentiality impact, no integrity impact, and low availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268929 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2023-22067
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the CORBA component could allow a remote attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268928 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Content Collector for Email 4.0.1
Content Collector for Microsoft SharePoint 4.0.1
Content Collector for File Systems 4.0.1

Remediation/Fixes

Product

| VRM|Remediation
—|—|—
Content Collector for Email| 4.0.1| Use Content Collector for Email 4.0.1.15 Interim Fix IF009
Content Collector for File Systems| 4.0.1| Use Content Collector for File Systems 4.0.1.15 Interim Fix IF009
Content Collector for Microsoft SharePoint| 4.0.1| Use Content Collector for Microsoft SharePoint 4.0.1.15 Interim Fix IF009

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcontent_collectorMatch4.0.0
OR
ibmcontent_collectorMatch4.0.1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.8%