Lucene search

K
ibmIBMF5CF7F2CB6BE6494CAB48CA1E79244378F054391A2FE0E62B263FF8630BF547F
HistoryJul 06, 2023 - 4:41 p.m.

Security Bulletin: IBM DataPower Gateway potentially vulnerable to Denial of Service (CVE-2023-2650)

2023-07-0616:41:23
www.ibm.com
29
ibm datapower gateway
denial of service
cve-2023-2650
openssl
remote attacker
cvss base score
it43933

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%

Summary

IBM has addressed the CVE

Vulnerability Details

CVEID:CVE-2023-2650
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a flaw when using OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/256611 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 10.0.1 10.0.1.0-10.0.1.13
IBM DataPower Gateway 10.5.0 10.5.0.0-10.5.0.5
IBM DataPower Gateway 10.5 CD 10.5.1.0

Remediation/Fixes

Affected Product Fix in version APAR

IBM DataPower Gateway 10.0.1

| 10.0.1.14| IT43933
IBM DataPower Gateway 10.5.0| 10.5.0.6| IT43933

The CVE will be addressed in the next release of IBM DataPower Gateway 10.5 CD

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch10.5.0
OR
ibmdatapower_gatewayMatch10.5.1
OR
ibmdatapower_gatewayMatch10.0.1

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%