Lucene search

K
ibmIBMC24C20B7CD3A6B07E59003737DFBE3DE203C17A8ACB472214D2C21502BB1EB07
HistoryNov 30, 2023 - 7:32 a.m.

Security Bulletin: Vulnerabilities in Apache Struts library affect Tivoli Netcool/OMNIbus WebGUI (CVE-2023-41835)

2023-11-3007:32:12
www.ibm.com
16
apache struts
tivoli netcool/omnibus
denial of service
vulnerability
fix pack 33

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%

Summary

Apache Struts is used by Tivoli Netcool/OMNIbus WebGUI as part of its web client component. The fix includes Apache Struts v2.5.32.

Vulnerability Details

CVEID:CVE-2023-41835
**DESCRIPTION:**Apache Struts is vulnerable to a denial of service, caused by an incomplete cleanup of the struts.multipart.saveDir directory after an upload request is denied. By sending a specially crafted Multipart request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/265930 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli Netcool/OMNIbus_GUI 8.1.x

Remediation/Fixes

Product VRMF Ticket Remediation/First Fix
Tivoli Netcool/OMNIbus WebGUI 8.1.0 KT59471 Apply Fix Pack 33
(Fix Pack for WebGUI 8.1.0 Fix Pack 33)

Workarounds and Mitigations

Upgrade to WebGUI 8.1.0 Fix Pack 33.

Affected configurations

Vulners
Node
ibmtivoli_netcool\/omnibusMatch8.1.0
CPENameOperatorVersion
tivoli netcool/omnibuseq8.1.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%

Related for C24C20B7CD3A6B07E59003737DFBE3DE203C17A8ACB472214D2C21502BB1EB07