Lucene search

K
ibmIBMD77354293ADDF3F8579814EAC2B35D20D0CD45ED626E77A317D6AFE7D4D18A9D
HistoryDec 02, 2022 - 11:51 p.m.

Security Bulletin: Vulnerability has been identified in WebSphere Application Server Liberty shipped with Cloud Pak System (CVE-2022-24839)

2022-12-0223:51:35
www.ibm.com
16
ibm cloud pak system
websphere application server
liberty
security bulletin
vulnerability
cve-2022-24839
fix
denial of service

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.1%

Summary

Vulnerability has been identified in WebSsphere Application Server Liberty shipped wioth Cloud Pak System. IBM Cloud Pak System ships with optional Single- Sign-On (SSO) feature. Information about a security vulnerability affecting IBM WebSphere Application Server Liberty have been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s) Affected Supporting Product(s) Version(s)
IBM Cloud Pak System 2.3 WebSphere Application Server - Liberty 9.0
IBM Cloud Pak System Software Suite 2.3.3.0 WebSphere Application Server - Liberty 9.0

Remediation/Fixes

Consult the following Security Bulletins for information and details about fixes. IBM strongly recommends to apply fix as soon as practical.

Security Bulletin: IBM WebSphere Application Server Liberty is vulnerable to a Denial of Service due to Neko HTML (CVE-2022-24839)

In order to apply the fix

1. Download the fix from IBM FixCentral

2. Upload the fix to Cloud Pak System

3. Apply the fix from CPS UI select WAS virtual system instance, manage, operations and fixpack, or through the command line.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_systemMatch2.3
VendorProductVersionCPE
ibmcloud_pak_system2.3cpe:2.3:a:ibm:cloud_pak_system:2.3:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.1%

Related for D77354293ADDF3F8579814EAC2B35D20D0CD45ED626E77A317D6AFE7D4D18A9D