Lucene search

K
ibmIBME17535934E07A35D1ADB74DFC7CB4663F55D0976B5E9AEDA40CE4417A43F4917
HistoryOct 20, 2023 - 9:35 a.m.

Security Bulletin: IBM App Connect Enterprise is vulnerable to a heap-based buffer overflow due to electron

2023-10-2009:35:15
www.ibm.com
54
ibm app connect enterprise
heap-based buffer overflow
electron
cve-2023-4863
google chrome
webp
cvss
ibm
fix pack

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.629

Percentile

97.9%

Summary

IBM App Connect Enterprise is vulnerable to a heap-based buffer overflow due to electron (CVE-2023-4863). Electron is used for Discovery Connectors in IBM App Connect Enterprise.

Vulnerability Details

CVEID:CVE-2023-4863
**DESCRIPTION:**Google Chrome is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by WebP. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/265660 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.9.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying the appropriate fix to IBM App Connect Enterprise

Product(s)

|

Version(s)

|

APAR

|

Remediation / Fix

—|—|—|—

IBM App Connect Enterprise

|

12.0.1.0 - 12.0.9.0

|

IT44660

|

The APAR (IT44660) is available from

IBM App Connect Enterprise v12 - Fix Pack 12.0.10.0

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.9.0
VendorProductVersionCPE
ibmapp_connect_enterprise*cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.629

Percentile

97.9%