Lucene search

K
ibmIBMF4D249F0788CC1520A0C1B4628180FD758B58DA0D1796655033120B8472F862C
HistoryJan 12, 2024 - 6:16 p.m.

Security Bulletin: A vulnerability in NSS may affect IBM Robotic Process Automation for Cloud Pak and result in a remote attacker obtaining sensitive information (CVE-2023-4421).

2024-01-1218:16:26
www.ibm.com
9
nss
ibm robotic process automation
cloud pak
remote attacker
sensitive information
cve-2023-4421
mozilla
cryptographic implementation
cvss
ibm
remediation
instructions

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.1%

Summary

NSS is used by IBM Robotic Process Automation for Cloud Pak as part of Watson NLP. (CVE-2023-4421).

Vulnerability Details

CVEID:CVE-2023-4421
**DESCRIPTION:**Mozilla Network Security Services (NSS), as used in Mozilla Firefox, could allow a remote authenticated attacker to obtain sensitive information, caused by a timing attack in the RSA operations due to incorrect cryptographic implementation. By using new tlsfuzzer code, an attacker could exploit this vulnerability to obtain sensitive information on the system.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268005 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.11, 23.0.0 - 23.0.11

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s) **Version(s) number and/or range ** Remediation/Fix/Instructions
IBM Robotic Process Automation for Cloud Pak 21.0.0 - 21.0.7.11 Update to 21.0.7.12 or higher using the following instructions.

IBM Robotic Process Automation for Cloud Pak

| 23.0.0 - 23.0.11| Update to 23.0.12 or higher using the following instructions.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrobotic_process_automationMatch21.0.0
OR
ibmrobotic_process_automationMatch21.0.7.11
OR
ibmrobotic_process_automationMatch23.0.0
OR
ibmrobotic_process_automationMatch23.0.11

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.1%

Related for F4D249F0788CC1520A0C1B4628180FD758B58DA0D1796655033120B8472F862C