Incorrect Comparison in babel - CVE-2023-45133

 

Incorrect Comparison in babel - CVE-2023-45133

Published: November 17, 2023


Vulnerability identifier: #VU83234
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45133
CWE-ID: CWE-697
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists in '@babel/traverse' and `babel-traverse`. A local user can execute arbitrary code during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods.


Affected software

babel
Cognos Dashboards on Cloud Pak for Data
DB2 Data Management Console
IBM Cloud Pak for Watson AIOps
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Security QRadar Network Threat Analytics
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
Debian Linux
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Maximo Application Suite
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
Bitbucket Data Center
IBM QRadar WinCollect Agent
IBM Cloud Pak for Business Automation
Splunk Enterprise Security (ES)
Juniper Secure Analytics (JSA)
IBM Security QRadar Analyst Workflow
IBM QRadar Use Case Manager
IBM DB2
Cloud Pak for Data
node-babel7 (Debian package)
Bitbucket Server

How to mitigate CVE-2023-45133

Install updates from vendor's website.

babel - addressed in versions 7.23.2, 8.0.0 alpha.4
DB2 Data Management Console - update to 3.1.13
QRadar User Behavior Analytics - update to 4.1.14
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
Splunk Enterprise Security (ES) - addressed in versions 7.1.2, 7.2.0, 7.3.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
IBM Maximo Application Suite - addressed in versions 8.10.6, 8.11.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-15, 2023.4.1-0
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Cloud Pak for Security - update to 1.11.2.0
IBM Planning Analytics Workspace - update to 2.0.93
Cloud Pak for Network Automation - update to 2.6.4
IBM Fusion HCI - update to 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.0
QRadar Deployment Intelligence App - update to 3.0.12
IBM QRadar Use Case Manager - update to 3.9.0
IBM DB2 - update to 4.8
Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
node-babel7 (Debian package) - addressed in versions 7.12.12+~cs150.141.84-6+deb11u1, 7.20.15+ds1+~cs214.269.168-3+deb12u1
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
IBM QRadar WinCollect Agent - update to 10.1.9
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5

External References

Related Security Bulletins