SB2023010611 - Improper verification of cryptographic signature in IBM Cloud Pak for Watson AIOps



SB2023010611 - Improper verification of cryptographic signature in IBM Cloud Pak for Watson AIOps

Published: January 6, 2023

Security Bulletin ID SB2023010611
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2021-44878)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists if an OpenID Connect provider supports the "none" algorithm, then pac4j does not refuse it without an explicit configuration on its side or for the "idtoken" response type. A remote attacker can bypass the token validation by injecting a malformed ID token using "none" as the value of "alg" key in the header with an empty signature value.


Remediation

Install update from vendor's website.