Lucene search

K
ibmIBME5FC7596E440DDFB76A2317DF01069E2A2B2F1D2C566D0B3B3B34DE479AF38A2
HistoryOct 28, 2022 - 9:34 p.m.

Security Bulletin: Vulnerability in IBM® Host Access Beans affects IBM Host Access Transformation Services

2022-10-2821:34:46
www.ibm.com
20
ibm
host access beans
transformation services
hats
vulnerability
cve-2021-38938
user credentials
fix
ibm support

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Summary

There is a vulnerability in IBM Host Access Beans 4 used by Host Access Transformation Services. Host Access Transformation Services has provided a fix for the applicable CVE. The CVE is listed as CVE-2021-38938.

Vulnerability Details

CVEID:CVE-2021-38938
**DESCRIPTION:**IBM Host Access Transformation Services (HATS) stores user credentials in plain clear text which can be read by a local user.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/210989 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
HATS 9.6 - 9.6.1.4
HATS 9.7 - 9.7.0.3

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by installing this fix or a newer iFix or Fix Pack.

Product VRMF APAR Remediation / First Fix File Name
_Host Access Transformation Services
_ 9.6 - 9.6.1.4 None

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm/Rational/Rational+Host+Access+Transformation+Services&release=9.6.1.4&platform=All&function=all

| 9.6.1.4-HATS-Fix-Pack
Host Access Transformation Services| 9.7 - 9.7.0.3| None|

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm/Rational/Rational+Host+Access+Transformation+Services&release=9.7.0.3&platform=All&function=all

| 9.7.0.3-HATS-Fix-Pack

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmhost_access_transformation_servicesMatch9.6
OR
ibmhost_access_transformation_servicesMatch9.7
VendorProductVersionCPE
ibmhost_access_transformation_services9.6cpe:2.3:a:ibm:host_access_transformation_services:9.6:*:*:*:*:*:*:*
ibmhost_access_transformation_services9.7cpe:2.3:a:ibm:host_access_transformation_services:9.7:*:*:*:*:*:*:*

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Related for E5FC7596E440DDFB76A2317DF01069E2A2B2F1D2C566D0B3B3B34DE479AF38A2