Lucene search

K
ibmIBMF19C8D7563A89D9E9758AF8E76750C8273CF070A7F665DCF0E4A4920DB69D169
HistoryFeb 08, 2024 - 6:01 p.m.

Security Bulletin: IBM Cloud Pak System is vulnerable to brute force account credentials attack [CVE-2023-38273]

2024-02-0818:01:33
www.ibm.com
10
ibm cloud pak system
brute force attack
inadequate account lockout
affected versions
upgrade
interim fix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

34.3%

Summary

IBM Cloud Pak System uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials [CVE-2023-38273]

Vulnerability Details

CVEID:CVE-2023-38273
**DESCRIPTION:**IBM Cloud Pak System uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260733 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak System 2.3.1.1, 2.3.2.0 (power)
IBM Cloud Pak System Software Suite 2.3.3.7 (power)
IBM Cloud Pak System 2.3.3.0 - 2.3.3.6 (intel)
IBM Cloud Pak System Software Suite 2.3.3.0 - 2.3.3.6 (intel)

Remediation/Fixes

For unsupported versions the recommendation is to upgrade to supported version of the product.

This security bulletin applies to Cloud Pak System, Cloud Pak System Software, Cloud Pak System Software Suite.

For Cloud Pak System V2.3.0.1, V2.3.1.1, V2.3.2.0, for Power

Upgrade to Cloud Pak System v2.3.3.7 and apply V2.3.3.7 Interim Fix 01 at IBM Fix Central.

information on upgrading here <https://www.ibm.com/support/pages/node/6982511&gt;

For Cloud Pak System V2.3.3.7 for Power

Apply Cloud Pak System V2.3.3.7 Interim Fix 01 at IBM Fix Central.

information on upgrading here <http://www.ibm.com/support/docview.wss?uid=ibm10887959&gt;

For IBM Cloud Pak System v2.3.3.0 through v2.3.3.6 for Intel

upgrade to Cloud Pak System 2.3.3.6. Ifix1,

apply IBM Cloud Pak System v2.3.3.6 Interim Fix 2 at Fix Central.

information on upgrading here <https://www.ibm.com/support/pages/node/7017280&gt;

For IBM Cloud Pak System V2.3.3.6 Interim Fix1,

Apply Cloud Pak System V2.3.3.6 Interim Fix 2 at Fix Central

information on upgrading here <http://www.ibm.com/support/docview.wss?uid=ibm10887959&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_systemMatch2.3
VendorProductVersionCPE
ibmcloud_pak_system2.3cpe:2.3:a:ibm:cloud_pak_system:2.3:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

34.3%

Related for F19C8D7563A89D9E9758AF8E76750C8273CF070A7F665DCF0E4A4920DB69D169