Lucene search

K
ibmIBMC0BCD9A9BF939458EA2B5D67C3BDE1D9300E1237CE433F37F5BD2E10E60A9568
HistoryFeb 07, 2024 - 3:45 p.m.

Security Bulletin: IBM DataPower Gateway vulnerable to unauthorized access in Redis

2024-02-0715:45:50
www.ibm.com
40
ibm datapower gateway
redis
vulnerability
fix
unauthorized access
race condition
umask
cve-2023-45145
security
b2b
rate-limiting
apar
it45065

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

10.5%

Summary

Redis is used in gateway peering, B2B and rate-limiting. IBM has updated Redis to address the vulnerability.

Vulnerability Details

CVEID:CVE-2023-45145
**DESCRIPTION:**Redis could allow a local authenticated attacker to bypass security restrictions, caused by a race condition when a permissive umask(2) is used during startup. By sending a specially crafted request, an attacker could exploit this vulnerability to establish an unauthorized connection.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/269075 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 10.5 CD 10.5.0-10.5.2
IBM DataPower Gateway 10.0.1 10.0.1.0-10.0.1.16
IBM DataPower Gateway 10.5.0 10.5.0.0-10.5.0.8

Remediation/Fixes

Affected Product Fixed in version APAR
IBM DataPower Gateway 10.5 CD 10.5.3 IT45065
IBM DataPower Gateway 10.0.1 10.0.1.17 IT45065
IBM DataPower Gateway 10.5.0 10.5.0.9 IT45065

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch10.5
OR
ibmdatapower_gatewayMatch10.5.0
OR
ibmdatapower_gatewayMatch10.0.1
VendorProductVersionCPE
ibmdatapower_gateway10.5cpe:2.3:a:ibm:datapower_gateway:10.5:*:*:*:*:*:*:*
ibmdatapower_gateway10.5.0cpe:2.3:a:ibm:datapower_gateway:10.5.0:*:*:*:*:*:*:*
ibmdatapower_gateway10.0.1cpe:2.3:a:ibm:datapower_gateway:10.0.1:*:*:*:*:*:*:*

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

10.5%