Lucene search

K
ibmIBMBF636C65A0B3404285677C4862BDC7113972D22C73F1DB36013C37412196E061
HistoryJun 30, 2023 - 1:42 p.m.

Security Bulletin: IBM Watson Explorer is affected by multiple vulnerabilities in Java

2023-06-3013:42:41
www.ibm.com
8
ibm watson explorer
java vulnerability
oracle java se
graalvm
analytical components
foundational components

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

51.8%

Summary

IBM Watson Explorer contains a vulnerable version of Java.

Vulnerability Details

CVEID:CVE-2023-21930
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the JSSE component could allow an unauthenticated attacker to cause high confidentiality impact and high integrity impact.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253115 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

CVEID:CVE-2023-21967
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the Hotspot component could allow a remote attacker to cause high confidentiality impact.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253166 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Explorer DAE
oneWEX Components

12.0.0.0, 12.0.0.1

12.0.1,

12.0.2.0 - 12.0.2.2,

12.0.3.0 - 12.0.3.11

IBM Watson Explorer DAE Analytical Components|

12.0.0.0, 12.0.0.1

12.0.1,

12.0.2.0 - 12.0.2.2,

12.0.3.0 - 12.0.3.11

IBM Watson Explorer DAE Foundational Components|

12.0.0.0, 12.0.0.1

12.0.1,

12.0.2.0 - 12.0.2.2,

12.0.3.0 - 12.0.3.11

IBM Watson Explorer Analytical Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 - 11.0.2.15
IBM Watson Explorer Foundational Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 - 11.0.2.15

Remediation/Fixes

| Affected Versions|How to acquire and apply the fix
—|—|—
IBM Watson Explorer Deep Analytics Edition Analytical Components| 12.0.0.0, 12.0.1.0, 12.0.2.0 - 12.0.2.2, 12.0.3.0 - 12.0.3.11|

Upgrade to Version 12.0.3.12.

See Watson Explorer Version 12.0.3.12 Analytical Components for download information and instructions.

IBM Watson Explorer Deep Analytics Edition Foundational Components Annotation Administration Console| 12.0.0.0, 12.0.1.0, 12.0.2.0 - 12.0.2.2, 12.0.3.0 - 12.0.3.11|

Upgrade to Version 12.0.3.12.

See Watson Explorer Version 12.0.3.12 Foundational Components for download information and instructions.

IBM Watson Explorer Deep Analytics Edition OneWEX Components| 12.0.0.0, 12.0.1.0, 12.0.2.0 - 12.0.2.2, 12.0.3.0 - 12.0.3.11|

Upgrade to Version 12.0.3.11.

See Watson Explorer Version 12.0.3.11 OneWEX Components for download information and instructions.

IBM Watson Explorer Analytical Components| 11.0.0.0 - 11.0.0.3,
11.0.1.0,
11.0.2.0 -
11.0.2.15|

Upgrade to Version 11.0.2.16.

See Watson Explorer Version 11.0.2.16 Analytical Components for download information and instructions.

IBM Watson Explorer Foundational Components Annotation Administration Console| 11.0.0.0 - 11.0.0.3,
11.0.1.0,
11.0.2.0 -
11.0.2.15|

Upgrade to Version 11.0.2.16.

See Watson Explorer Version 11.0.2.16 Foundational Components for download information and instructions.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwatson_queryMatch11.0.0
OR
ibmwatson_queryMatch11.0.1
OR
ibmwatson_queryMatch11.0.2
OR
ibmwatson_queryMatch12.0.0
OR
ibmwatson_queryMatch12.0.1
OR
ibmwatson_queryMatch12.0.2
OR
ibmwatson_queryMatch12.0.3

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

51.8%