SB2023060118 - Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps 



SB2023060118 - Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps

Published: June 1, 2023

Security Bulletin ID SB2023060118
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2023-20860)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an input validation error caused by using the wildcard ("**") as a pattern in Spring Security configuration with the mvcRequestMatcher, which creates a mismatch in pattern matching between Spring Security and Spring MVC. A remote attacker can bypass certain security restrictions.


2) Improper Control of Dynamically-Managed Code Resources (CVE-ID: CVE-2023-29199)

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to an error within the source code transformer. A remote user can bypass handleException() and leak unsanitized host exceptions. The obtain information can be used to escape the sandbox and run arbitrary code in host context.


Remediation

Install update from vendor's website.