Improper Certificate Validation in MongoDB - CVE-2023-1409
Published: November 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists if the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux). A remote attacker can exploit vulnerability to modify data on the system.
Affected software
IBM Spectrum Protect Plus
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Storage Copy Data Management
How to mitigate CVE-2023-1409
IBM Spectrum Protect Plus - update to 10.1.17.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
Storage Copy Data Management - update to 2.2.23.0
IBM Automation Decision Services - update to 23.0.1 IF003