Lucene search

K
ibmIBMC85A1C4DF786595C0DA54F45957FBAF822AB6BBB7D329597866854B83F4E5E41
HistoryOct 13, 2023 - 11:24 a.m.

Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus are vulnerable to a denial of service

2023-10-1311:24:31
www.ibm.com
13
ibm
app connect enterprise
integration bus
vulnerability
denial of service
windows
cve-2023-45176
cvss
fix
apar
ph57096

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%

Summary

IBM App Connect Enterprise and IBM Integration Bus are vulnerable to a denial of service for integration nodes on Windows (CVE-2023-45176)

Vulnerability Details

CVEID:CVE-2023-45176
**DESCRIPTION:**IBM App Connect Enterprise and IBM Integration Bus are vulnerable to a denial of service for integration nodes on Windows.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/267998 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.10.0
IBM App Connect Enterprise 11.0.0.1 - 11.0.0.23
IBM Integration Bus 10.1 - 10.1.0.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to****IBM Integration Bus

Product(s) Version(s) APAR Remediation / Fix
IBM App Connect Enterprise 12.0.1.0 - 12.0.10.0 PH57096

Interim fix for APAR (PH57096) is available to apply to 12.0.10.0 from Fix Central

IBM App Connect Enterprise| 11.0.0.1 - 11.0.0.23| PH57096|

Interim fix for APAR (PH57096) is available to apply to 11.0.0.22 and 11.0.0.23 from Fix Central

IBM Integration Bus| 10.1 - 10.1.0.1| PH57096|

Interim fix for APAR (PH57096) is available to apply to 10.1.0.1 from Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.10.0
OR
ibmapp_connect_enterpriseRange11.0.0.1
OR
ibmapp_connect_enterpriseRange11.0.0.23
OR
ibmintegration_busRange10.1
OR
ibmintegration_busRange10.1.0.1

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%

Related for C85A1C4DF786595C0DA54F45957FBAF822AB6BBB7D329597866854B83F4E5E41