SB2022110919 - Multiple vulnerabilities in IBM Cloud Application Business Insights
Published: November 9, 2022 Updated: January 22, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2022-3602)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing the email address field inside X.509 certificate. A remote attacker can supply a specially crafted certificate to the application, trigger a 4-byte buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system but requires that either a CA signs the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.
2) Buffer overflow (CVE-ID: CVE-2022-3786)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The
vulnerability exists due to a boundary error when processing the email
address field length inside a X.509 certificate. A remote attacker can supply a
specially crafted certificate to the application, trigger a buffer overflow and crash the application.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerabilities-might-impact-ibm-cloud-application-business-insights-cve-2022-3602-cve-2022-3786/"
- https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerabilities-might-impact-ibm-cloud-application-business-insights-cve-2022-3602-cve-2022-3786/</a><br>
- https://www.ibm.com/support/pages/node/6837817<br><br></p>