Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 17 |
CVE-ID | CVE-2023-30585 CVE-2023-30588 CVE-2023-30584 CVE-2023-30583 CVE-2023-30587 CVE-2023-30586 CVE-2023-30582 CVE-2023-30590 CVE-2023-30589 CVE-2023-30581 CVE-2023-32004 CVE-2023-32002 CVE-2023-32559 CVE-2023-32558 CVE-2023-32003 CVE-2023-32006 CVE-2023-32005 |
CWE-ID | CWE-426 CWE-20 CWE-22 CWE-264 CWE-284 CWE-1068 CWE-444 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
IBM Business Automation Workflow Server applications / Other server solutions |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 17 vulnerabilities.
EUVDB-ID: #VU77601
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2023-30585
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the way Node.js (.msi version) installation process handles a missing %USERPROFILE% environment variable. If the variable is not set, the .msi installer will try to include a current working directory into the search path and will libraries in an unsafe manner. A local user can place a malicious file on the victim's system and execute arbitrary code with elevated privileges.
The vulnerability affects Windows installators only.
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77604
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30588
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied public key within the crypto.X509Certificate() API. A remote user can pass an invalid public key to the application and perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77594
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30584
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error within the experimental permission model when verifying file permissions. A remote user can send a specially crafted request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77599
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2023-30583
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to a missing check in the fs.openAsBlob() API. A remote user leverage fs.openAsBlob() to bypass the experimental permission model when using the file system read restriction with the --allow-fs-read flag.
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77595
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30587
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can exploit the Worker class's ability to create an "internal worker" with the kIsInternal Symbol to bypass restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector).
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77603
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30586
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to application allows loading arbitrary OpenSSL engines when the experimental permission model is enabled. A remote user can use the crypto.setEngine() API to bypass the permission model when called with a compatible OpenSSL engine and disable the permission model in the host process by manipulating the process's stack memory to locate the permission model Permission::enabled_ in the host process's heap memory.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77596
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2023-30582
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to an error within the experimental permission model when the --allow-fs-read flag is used with a non-* argument. An inadequate permission model fails to restrict file watching through the fs.watchFile API and result in an ability of a remote user to monitor files that they do not have explicit read access to.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77606
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30590
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to inconsistency between implementation and documented design within the generateKeys() API function. The documented behavior is different from the actual behavior, and this difference could lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77605
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30589
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests in the llhttp parser. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77586
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-30581
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the use of proto in process.mainModule.proto.require(). This allows to bypass the policy mechanism and require modules outside of the policy.json definition.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79337
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-32004
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to improper handling of Buffers in file system APIs. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79332
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-32002
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improperly imposed security restrictions for the Module._load() method. A remote attacker can bypass the policy mechanism and include modules outside of the policy.json definition for a given module.
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79335
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-32559
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79336
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-32558
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the deprecated API process.binding(). A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79340
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2023-32003
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to a missing check in the fs.mkdtemp() API. A remote attacker can bypass the permission model check using a path traversal attack in fs.mkdtemp() and fs.mkdtempSync().
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79334
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-32006
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
Install update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU79339
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2023-32005
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to an inadequate permission model that fails to restrict file stats through the fs.statfs API. A remote user can retrieve stats from files that they do not have explicit read access to.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Business Automation Workflow: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7039262
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?