Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server - CVE-2023-50313

 

Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server - CVE-2023-50313

Published: April 4, 2024


Vulnerability identifier: #VU88120
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50313
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker in adjacent network to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. An attacker in adjacent network can gain unauthorized access to sensitive information on the system.


Affected software

IBM WebSphere Application Server
IBM Business Automation Workflow
IBM Rational ClearQuest
IBM Rational ClearCase
WebSphere Service Registry and Repository
IBM Tivoli System Automation Application Manager
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Operations Analytics Predictive Insights
IBM Intelligent Operations Center
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Maximo Asset Management
WebSphere Remote Server
IBM Security Verify Governance
InfoSphere Master Data Management
Jazz for Service Management
IBM Tivoli Monitoring
IBM Maximo Application Suite - Manage Component
Intelligent Operations Center for Emergency Management
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor

How to mitigate CVE-2023-50313

Install updates from vendor's website.

Jazz for Service Management - update to 1.1.3.21
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11

External References

Related Security Bulletins