Lucene search

K
ibmIBMD3ABF9DE11335EA689A2AEDE84CE7F8800EF036B794FACB66353634CC3B24A6D
HistoryJun 20, 2023 - 4:04 p.m.

Security Bulletin: IBM Storage Protect server is vulnerable to a denial of service attack due to Golang Go (CVE-2022-41723)

2023-06-2016:04:54
www.ibm.com
18
ibm storage protect server
golang go
denial of service
vulnerability
cve-2022-41723
ossm
hpack decoder
http/2 stream
cpu consumption
ibm
aix linux windows
fix
ibm support
security bulletin

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.03

Percentile

91.0%

Summary

IBM Storage Protect Server component OSSM may be vulnerable in Golang Go, causing denial of service

Vulnerability Details

CVEID:CVE-2022-41723
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw in the HPACK decoder. By sending a specially-crafted HTTP/2 stream, a remote attacker could exploit this vulnerability to cause excessive CPU consumption, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/247965 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Protect Server 8.1

Remediation/Fixes

IBM Storage Protect Server Affected Versions Fixing Level Platform Link to Fix and Instructions
8.1.0.000 - 8.1.18.xxx 8.1.19 AIX Linux Windows <https://www.ibm.com/support/pages/node/6988821&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmstorage_protectMatch8.1
VendorProductVersionCPE
ibmstorage_protect8.1cpe:2.3:a:ibm:storage_protect:8.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.03

Percentile

91.0%