Lucene search

K
ibmIBMC8985B8D9828F235076A7AAE73AD7B6920214D849DE03E89F2E31FB3FFB406C5
HistoryJul 18, 2024 - 7:35 p.m.

Security Bulletin: IBM Match 360 vulnerable to denial of service due to jose4j in IBM WebSphere Application Server Liberty (CVE-2023-51775)

2024-07-1819:35:22
www.ibm.com
3
ibm match 360
denial of service
jose4j
websphere application server liberty
vulnerability
icp

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

Summary

IBM Match 360 is vulnerable to jose4j used within IBM WebSphere Application Server Liberty. jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Vulnerability Details

CVEID:CVE-2023-51775
**DESCRIPTION:**jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/275907 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ICP - IBM Match 360 All

Remediation/Fixes

Upgrade IBM Match 360 services to version 5.0.1 or higher. Alternatively IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the APAR PH60199 and APAR PH60195. To determine if a feature is enabled for IBM WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_dataMatch4.
OR
ibmcloud_pak_for_dataMatch.
VendorProductVersionCPE
ibmcloud_pak_for_data4.cpe:2.3:a:ibm:cloud_pak_for_data:4.:*:*:*:*:*:*:*
ibmcloud_pak_for_data.cpe:2.3:a:ibm:cloud_pak_for_data:.:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High