Lucene search

K
ibmIBMCE55CEA60DBFCAB35B9CF839647118B186BE3AD37DE07210FF3DA7AD34966F19
HistoryMar 01, 2024 - 10:33 a.m.

Security Bulletin: Control Access issues in PCOMM

2024-03-0110:33:09
www.ibm.com
16
ibm pcomm
vulnerability
privilege escalation
version 14.0.5
version 14.0.6
version 15.0.0

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Summary

There is a vulnerability in IBM Person Communications(PCOMM) . Person Communications has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2023-37410
**DESCRIPTION:**IBM Personal Communications could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260138 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
PCOMM 14.0.5
PCOMM 14.0.6
PCOMM 15.0.0

Remediation/Fixes

For Client Fix

Upgrade to fixed updated PCOMM versions from the following location:

Version 14:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm/Rational/IBM+Personal+Communications&release=14.0.6&platform=All&function=all

Version 15:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm/Rational/IBM+Personal+Communications&release=15.0.1&platform=All&function=all

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmpersonal_communicationsMatch14.05
OR
ibmpersonal_communicationsMatch14.06
OR
ibmpersonal_communicationsMatch15.0.0
VendorProductVersionCPE
ibmpersonal_communications14.05cpe:2.3:a:ibm:personal_communications:14.05:*:*:*:*:*:*:*
ibmpersonal_communications14.06cpe:2.3:a:ibm:personal_communications:14.06:*:*:*:*:*:*:*
ibmpersonal_communications15.0.0cpe:2.3:a:ibm:personal_communications:15.0.0:*:*:*:*:*:*:*

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for CE55CEA60DBFCAB35B9CF839647118B186BE3AD37DE07210FF3DA7AD34966F19