SB2023100910 - Multiple vulnerabilities in IBM Spectrum Control
Published: October 9, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2023-28867)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a crafted GraphQL query that causes stack consumption.
2) Insecure Temporary File (CVE-ID: CVE-2023-0482)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to insecure creation of temporary files. A local user can gain access to sensitive information.
3) Improper validation of certificate with host mismatch (CVE-ID: CVE-2022-39161)
The vulnerability allows a remote user to perform MitM attack.
The vulnerability exists due to improper certificate validation issued by a trusted CA when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server. A remote user can perform a man-in-the-middle (MitM) attack and gain access to sensitive information.
4) Information disclosure (CVE-ID: CVE-2022-45787)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper laxist permissions on the temporary files. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.