VDB
CVE-2023-28366
CVE-2023-28366
PUBLISHED
CVSS 8.699999809265137 HIGH
In IBM Integration Bus existieren mehrere Schwachstellen. Diese bestehen in Komponenten von Drittanbietern und sind auf Speicherlecks sowie nicht abgefangene Excepetions zurückzuführen. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um einen Denial of Service Zustand herbeizuführen.
EPSS 0.12% · 30.2th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.12%
30.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | IBM Integration Bus 10.1 - 10.1.0.1 |
Exploit Intelligence
- https://github.com/eclipse/mosquitto/compare/v2.0.15...v2.0.16 (circl)
- https://www.compass-security.com/fileadmin/Research/Advisories/2023_02_CSNC-2023-001_Eclipse_Mosquitto_Memory_Leak.txt (circl)
- https://mosquitto.org/blog/2023/08/version-2-0-16-released/ (circl)
- https://github.com/eclipse/mosquitto/commit/6113eac95a9df634fbc858be542c4a0456bfe7b9 (circl)
- FEDORA-2023-9adc4be8b0 (circl)
- DSA-5511 (circl)
- GLSA-202401-09 (circl)
Timeline
- Sep 1, 2023 CVE Published
- Sep 2, 2023 EPSS Score
- Oct 5, 2023 EPSS Score
- Nov 7, 2023 EPSS Score
- Dec 9, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
- Mar 17, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
- May 21, 2024 EPSS Score
- Jun 23, 2024 EPSS Score
- Jul 26, 2024 EPSS Score
- Aug 28, 2024 EPSS Score