VDB
CVE-2023-30441
CVE-2023-30441
PUBLISHED
CVSS 8.699999809265137 HIGH
Es existiert eine Schwachstelle in IBM Java und IBM Java SDK aufgrund von verschiedenen Fehlern in Komponenten und speziellen Konfigurationen. Ein entfernter, anonymer Angreifer kann dies ausnutzen, um Informationen offenzulegen.
EPSS 0.06% · 18.9th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.06%
18.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | IBM DB2 10.5 | |
| IBM | IBM WebSphere Service Registry and Repository 8.5.x | |
| IBM | IBM MQ 9.1 | |
| IBM | IBM Rational Business Developer 9.6 | |
| IBM | IBM Tivoli Network Manager 3.9 | |
| IBM | IBM AIX 7.3 | |
| IBM | IBM Business Automation Workflow < 21.0.3-IF020 | |
| IBM | IBM Storwize | |
| IBM | IBM DB2 11.5 | |
| IBM | IBM MQ Appliance 9.2 CD | |
| IBM | IBM MQ 9.0 | |
| IBM | IBM Tivoli Netcool/OMNIbus 8.1.0 | |
| IBM | IBM WebSphere Application Server Liberty | |
| IBM | IBM MQ 9.2 | |
| IBM | IBM Tivoli Network Manager 4.2 | |
| IBM | IBM Security Guardium Key Lifecycle Manager 4.2 | |
| IBM | IBM MQ Appliance 9.2 LTS | |
| IBM | IBM QRadar SIEM 7.5 | |
| IBM | IBM Rational Business Developer 9.7 | |
| IBM | IBM Business Automation Workflow < 22.0.2-IF004 |
…and 20 more
Exploit Intelligence
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
- cve-2023-22527-yara.yar (github-yara)
Timeline
- Apr 20, 2023 CVE Published
- Apr 30, 2023 EPSS Score
- Jun 6, 2023 EPSS Score
- Jul 13, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Nov 2, 2023 EPSS Score
- Dec 9, 2023 EPSS Score
- Jan 15, 2024 EPSS Score
- Feb 8, 2024 PoC Published
- Feb 21, 2024 EPSS Score
- Mar 29, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1055.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1055 advisory
- https://www.ibm.com/support/pages/node/7066504 advisory
- https://www.ibm.com/support/pages/node/7061888 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-June/015172.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-June/015130.html advisory
- https://www.ibm.com/support/pages/node/6998795 advisory
- https://www.ibm.com/support/pages/node/6999115 advisory
- https://www.ibm.com/support/pages/node/6998353 advisory
- https://aix.software.ibm.com/aix/efixes/security/java_may2023_advisory.asc advisory
- https://www.ibm.com/support/pages/node/6995893 advisory
- https://www.ibm.com/support/pages/node/6995527 advisory
- https://www.ibm.com/support/pages/node/6987155 advisory
- https://www.ibm.com/support/pages/node/6995533 advisory
- https://www.ibm.com/support/pages/node/6991279 advisory
- https://www.ibm.com/support/pages/node/6989589 advisory
- https://www.ibm.com/support/pages/node/6987769 advisory
- https://www.ibm.com/support/pages/node/6987835 advisory
- https://www.ibm.com/support/pages/node/6987167 advisory
- https://www.ibm.com/support/pages/node/6987033 advisory
…and 7 more