Lucene search

K
ibmIBMEE7C2886F57225FEC8741732FACCE555D2DD0CF394E26B96FEE008FD276BF30E
HistoryOct 05, 2023 - 8:23 p.m.

Security Bulletin: IBM Spectrum Conductor with json-smart-v2 is vulnerable to a denial of service

2023-10-0520:23:00
www.ibm.com
29
ibm spectrum conductor
json-smart-v2
denial of service
vulnerability
fix 601712
stack exhaustion

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

46.1%

Summary

IBM Spectrum Conductor with json-smart-v2 is vulnerable to a denial of service

Vulnerability Details

CVEID:CVE-2023-1370
**DESCRIPTION:**netplex json-smart-v2 is vulnerable to a denial of service, caused by not limiting the nesting of arrays or objects. By sending a specially crafted input, a remote attacker could exploit this vulnerability to cause a stack exhaustion and crash the software.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/249885 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Conductor 2.5.0
IBM Spectrum Conductor 2.5.1

Remediation/Fixes

IBM strongly suggests the following remediation or fix:

Upgrade to the latest versions of IBM Spectrum Conductor 2.5.1 FP2 (IBM Spectrum Conductor 2.5.1 with Fix 601712).

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmspectrum_controlMatch2.5.1
VendorProductVersionCPE
ibmspectrum_control2.5.1cpe:2.3:a:ibm:spectrum_control:2.5.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

46.1%