CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
Percentile
40.4%
IBM UrbanCode Build is vulnerable to CVE-2023-28708. IBM has addressed these vulnerabilities by updating Apache Tomcat Server.
CVEID:CVE-2023-28708
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by the missing of secure attribute in some configurations for JSESSIONID Cookie when using the RemoteIpFilter. By sniffing the network traffic, an attacker could exploit this vulnerability to obtain session cookie information, and use this information to launch further attacks against the affected system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/250740 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
UCB - IBM UrbanCode Build | 6.1.x - 6.1.7.7 |
IBM strongly recommends addressing the vulnerability now by upgrading to IBM UrbanCode Build 6.1.7.9 or above.
Affected Supporting Product(s)
|
Remediation/Fix
—|—
IBM UrbanCode Build 6.x - 6.1.7.7
|
Download IBM UrbanCode Build 6.1.7.9
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | rational_build_forge | 6.1.7.9 | cpe:2.3:a:ibm:rational_build_forge:6.1.7.9:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
Percentile
40.4%