NULL pointer dereference in OpenLDAP - CVE-2023-2953
Published: June 13, 2023
Vulnerability identifier: #VU77252
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2953
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the ber_memalloc_x() function. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
OpenLDAP
Oracle Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
DataStax Hyper-Converged Database
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
ObjectScale
Platform Automation Toolkit
IBM QRadar Incident Forensics
Dell PowerProtect Cyber Recovery
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Cryostat
Oracle Communications Cloud Native Core Certificate Management
Cluster Observability Operator
Submariner
Migration Toolkit for Runtimes
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Cloud Pak for Business Automation
Voice Gateway
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
slapd (Ubuntu package)
openldap2-ppolicy-check-password-debuginfo
openldap2-ppolicy-check-password
compat-libldap-2_3-0-debuginfo
compat-libldap-2_3-0
openldap
openldap2-client
openldap2-back-meta-debuginfo
openldap2-client-debuginfo
openldap2-back-meta
libldap-2_4-2
openldap2
libldap-2_4-2-debuginfo
openldap2-devel
openldap2-debugsource
openldap2-debuginfo
openldap2-back-perl
openldap2-devel-static
openldap2-back-perl-debuginfo
openldap2-doc
libldap-2_4-2-debuginfo-32bit
libldap-2_4-2-32bit
openldap-devel
openldap-clients
openldap-servers
openldap2-back-sql-debuginfo
openldap2-contrib-debuginfo
openldap2-back-sock
openldap2-contrib
openldap2-back-sock-debuginfo
libldap-data
openldap2-devel-32bit
libldap-2_4-2-32bit-debuginfo
openldap2-back-sql
openldap-debugsource
openldap-debuginfo
openldap-help
openldap (Red Hat package)
BIG-IP
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Console
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Security Verify Access
IBM CICS TX Advanced
Oracle Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
DataStax Hyper-Converged Database
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
ObjectScale
Platform Automation Toolkit
IBM QRadar Incident Forensics
Dell PowerProtect Cyber Recovery
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Cryostat
Oracle Communications Cloud Native Core Certificate Management
Cluster Observability Operator
Submariner
Migration Toolkit for Runtimes
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Cloud Pak for Business Automation
Voice Gateway
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
slapd (Ubuntu package)
openldap2-ppolicy-check-password-debuginfo
openldap2-ppolicy-check-password
compat-libldap-2_3-0-debuginfo
compat-libldap-2_3-0
openldap
openldap2-client
openldap2-back-meta-debuginfo
openldap2-client-debuginfo
openldap2-back-meta
libldap-2_4-2
openldap2
libldap-2_4-2-debuginfo
openldap2-devel
openldap2-debugsource
openldap2-debuginfo
openldap2-back-perl
openldap2-devel-static
openldap2-back-perl-debuginfo
openldap2-doc
libldap-2_4-2-debuginfo-32bit
libldap-2_4-2-32bit
openldap-devel
openldap-clients
openldap-servers
openldap2-back-sql-debuginfo
openldap2-contrib-debuginfo
openldap2-back-sock
openldap2-contrib
openldap2-back-sock-debuginfo
libldap-data
openldap2-devel-32bit
libldap-2_4-2-32bit-debuginfo
openldap2-back-sql
openldap-debugsource
openldap-debuginfo
openldap-help
openldap (Red Hat package)
BIG-IP
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Console
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Security Verify Access
IBM CICS TX Advanced
How to mitigate CVE-2023-2953
Install updates from vendor's website.
OpenLDAP - update to 2.5.14
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Voice Gateway - update to 1.0.8.12
DataStax Hyper-Converged Database - update to 1.2.5
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Qradar SIEM - addressed in versions 7.5.0 Update Pack 9 IF01, 7.5.0 Update Pack 10
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
slapd (Ubuntu package) - addressed in versions Ubuntu Pro, 2.4.49+dfsg-2ubuntu1.10, 2.5.16+dfsg-0ubuntu0.22.04.2
Cluster Observability Operator - update to 0.4.1
Submariner - update to 0.17.6
Red Hat OpenShift Serverless - update to 1
Migration Toolkit for Runtimes - update to 1.2.7
openldap2-ppolicy-check-password-debuginfo - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
openldap2-ppolicy-check-password - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
ObjectScale - update to 1.4.0
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
compat-libldap-2_3-0-debuginfo - update to 2.3.37-45.1
compat-libldap-2_3-0 - update to 2.3.37-45.1
Multicluster Engine for Kubernetes - update to 2.4.6
openldap - addressed in versions 2.4.40-16.37, 2.4.57-6
openldap2-client - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-client-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debugsource - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel-static - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-doc - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo-32bit - update to 2.4.41-22.19.1
libldap-2_4-2-32bit - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap-devel - update to 2.4.46-19
openldap-clients - update to 2.4.46-19
openldap - update to 2.4.46-19
openldap-servers - update to 2.4.46-19
openldap2-back-sql-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-contrib-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sock - update to 2.4.46-150200.14.14.1
openldap2-contrib - update to 2.4.46-150200.14.14.1
openldap2-back-sock-debuginfo - update to 2.4.46-150200.14.14.1
libldap-data - update to 2.4.46-150200.14.14.1
openldap2-devel-32bit - update to 2.4.46-150200.14.14.1
libldap-2_4-2-32bit-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sql - update to 2.4.46-150200.14.14.1
openldap - update to 2.4.50-8
openldap-clients - update to 2.4.50-8
openldap-debugsource - update to 2.4.50-8
openldap-debuginfo - update to 2.4.50-8
openldap-devel - update to 2.4.50-8
openldap-servers - update to 2.4.50-8
openldap-help - update to 2.4.50-8
openldap (Red Hat package) - addressed in versions 2.6.2-1.el9_0.1, 2.6.2-3.el9_2.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5
VMware Tanzu Operations Manager - update to 2.10.60
VMware Tanzu Application Service for VMs - addressed in versions 3.0.14, 4.0.5
Isolation Segment - addressed in versions 3.0.14, 4.0.5
Red Hat OpenShift Dev Spaces - update to 3.15.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.77, 4.13.45, 4.14.32, 4.14.33, 4.14.53, 4.15.21, 4.15.52
OpenShift Logging - update to 5.6.21
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Security Verify Access - update to 10.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix27
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Voice Gateway - update to 1.0.8.12
DataStax Hyper-Converged Database - update to 1.2.5
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Qradar SIEM - addressed in versions 7.5.0 Update Pack 9 IF01, 7.5.0 Update Pack 10
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
slapd (Ubuntu package) - addressed in versions Ubuntu Pro, 2.4.49+dfsg-2ubuntu1.10, 2.5.16+dfsg-0ubuntu0.22.04.2
Cluster Observability Operator - update to 0.4.1
Submariner - update to 0.17.6
Red Hat OpenShift Serverless - update to 1
Migration Toolkit for Runtimes - update to 1.2.7
openldap2-ppolicy-check-password-debuginfo - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
openldap2-ppolicy-check-password - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
ObjectScale - update to 1.4.0
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
compat-libldap-2_3-0-debuginfo - update to 2.3.37-45.1
compat-libldap-2_3-0 - update to 2.3.37-45.1
Multicluster Engine for Kubernetes - update to 2.4.6
openldap - addressed in versions 2.4.40-16.37, 2.4.57-6
openldap2-client - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-client-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debugsource - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel-static - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-doc - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo-32bit - update to 2.4.41-22.19.1
libldap-2_4-2-32bit - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap-devel - update to 2.4.46-19
openldap-clients - update to 2.4.46-19
openldap - update to 2.4.46-19
openldap-servers - update to 2.4.46-19
openldap2-back-sql-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-contrib-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sock - update to 2.4.46-150200.14.14.1
openldap2-contrib - update to 2.4.46-150200.14.14.1
openldap2-back-sock-debuginfo - update to 2.4.46-150200.14.14.1
libldap-data - update to 2.4.46-150200.14.14.1
openldap2-devel-32bit - update to 2.4.46-150200.14.14.1
libldap-2_4-2-32bit-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sql - update to 2.4.46-150200.14.14.1
openldap - update to 2.4.50-8
openldap-clients - update to 2.4.50-8
openldap-debugsource - update to 2.4.50-8
openldap-debuginfo - update to 2.4.50-8
openldap-devel - update to 2.4.50-8
openldap-servers - update to 2.4.50-8
openldap-help - update to 2.4.50-8
openldap (Red Hat package) - addressed in versions 2.6.2-1.el9_0.1, 2.6.2-3.el9_2.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5
VMware Tanzu Operations Manager - update to 2.10.60
VMware Tanzu Application Service for VMs - addressed in versions 3.0.14, 4.0.5
Isolation Segment - addressed in versions 3.0.14, 4.0.5
Red Hat OpenShift Dev Spaces - update to 3.15.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.77, 4.13.45, 4.14.32, 4.14.33, 4.14.53, 4.15.21, 4.15.52
OpenShift Logging - update to 5.6.21
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Security Verify Access - update to 10.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix27
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
External References
Related Security Bulletins
- Denial of service in OpenLDAP
- SUSE update for openldap2
- SUSE update for openldap2
- SUSE update for openldap2
- Ubuntu update for openldap
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- VMware Tanzu products update for OpenLDAP
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Amazon Linux AMI update for openldap
- Multiple vulnerabilities in Dell Data Protection Central
- Ubuntu update for openldap
- openEuler update for openldap
- NULL pointer dereference in IBM CICS TX Advanced
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5.0
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Cluster Observability Operator
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Certificate Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Denial of service in F5 BIG-IP OpenLDAP component
- Denial of service in F5OS OpenLDAP component
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Security Verify Access
- Amazon Linux AMI update for openldap
- Anolis OS update for openldap
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 9 update for openldap
- Red Hat Enterprise Linux 9 update for openldap
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Submariner 0.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM DataStax Hyper-Converged Database