Lucene search

K
ibmIBMEB3EC5BD028448CA4E372554602CB07D9746DA8A00C55DA7599B4D57FAC2152F
HistoryJan 24, 2023 - 10:51 a.m.

Security Bulletin: IBM Security SOAR is using a component with known vulnerabilities (CVE-2020-10735)

2023-01-2410:51:23
www.ibm.com
41
ibm security soar
python vulnerability
update
cve-2020-10735
denial of service

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

77.9%

Summary

IBM Security SOAR uses an older version of Python that may be identified and exploited. An update has been released which addresses these issues. It is recommended upgrading to Version 47.2 or later of IBM Security SOAR.

Vulnerability Details

CVEID:CVE-2020-10735
**DESCRIPTION:**Python is vulnerable to a denial of service, caused by the failure to limit amount of digits converting text to int by the int() type in PyLong_FromString(). A remote attacker could exploit this vulnerability to consume all available resources.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/235840 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security SOAR 47.1 and earlier.

Remediation/Fixes

IBM encourages customers to promptly update their systems.

Users must upgrade to v47.2 or higher of IBM SOAR in order to obtain a fix for this vulnerability.

You can upgrade the platform and apply the security updates by following the instructions in the “Upgrade Procedure” section in the IBM Documentation

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm®_security_soarRange47.1
CPENameOperatorVersion
ibm security soarle47.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

77.9%