VDB
CVE-2023-31582
CVE-2023-31582
PUBLISHED
Es besteht eine Schwachstelle in IBM Business Automation Workflow. Dieser Fehler besteht im Jose4J-Paket und wird dadurch verursacht, dass eine niedrige Iterationszahl von 1000 oder weniger zugelassen wird. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um gehashte Passwortwerte zu erhalten.
EPSS 0.17% · 37.7th percentile
Risk Scores
EPSS Score
0.17%
37.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Communications <= 9.0.2.0.1 | |
| Oracle | Oracle Communications 23.1.0 | |
| Atlassian | Atlassian Bamboo <9.2.7 | |
| NetApp | NetApp ActiveIQ Unified Manager | |
| Oracle | Oracle Communications 23.1.4 | |
| IBM | IBM QRadar SIEM | |
| Atlassian | Atlassian Confluence <8.6.2 | |
| IBM | IBM QRadar SIEM <=7.5.0 UP8 | |
| Atlassian | Atlassian Confluence <8.7.1 | |
| Atlassian | Atlassian Bitbucket <8.9.7 | |
| Atlassian | Atlassian Bitbucket <8.12.4 | |
| Oracle | Oracle Communications 12.6.1.0.0 | |
| Atlassian | Atlassian Bitbucket <8.14.2 | |
| Atlassian | Atlassian Jira Service Management <5.4.12 | |
| Oracle | Oracle Communications 23.1.3 | |
| Oracle | Oracle Communications 23.3.1 | |
| Red Hat | Red Hat JBoss A-MQ Clients 3 | |
| Oracle | Oracle Communications 23.4.0 | |
| Red Hat | Red Hat Enterprise Linux | |
| Atlassian | Atlassian Confluence <8.5.4 |
…and 23 more
Exploit Intelligence
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
- druid-612f0710.json (github-poc)
Timeline
- Oct 24, 2023 CVE Published
- Oct 25, 2023 EPSS Score
- Nov 25, 2023 EPSS Score
- Dec 26, 2023 EPSS Score
- Jan 26, 2024 EPSS Score
- Feb 26, 2024 EPSS Score
- Mar 28, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- May 29, 2024 EPSS Score
- Jun 29, 2024 EPSS Score
- Jul 30, 2024 EPSS Score
- Aug 30, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3070.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3070 advisory
- https://access.redhat.com/errata/RHSA-2023:7678 advisory
- https://access.redhat.com/errata/RHSA-2023:7697 advisory
- https://confluence.atlassian.com/security/security-bulletin-december-12-2023-1319249520.html advisory
- https://access.redhat.com/errata/RHSA-2024:0705 advisory
- https://access.redhat.com/errata/RHSA-2024:0903 advisory
- https://access.redhat.com/errata/RHSA-2024:2945 advisory
- https://access.redhat.com/errata/RHSA-2024:3354 advisory
- https://access.redhat.com/errata/RHSA-2024:6536 advisory
- https://www.ibm.com/support/pages/node/7248128 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3071.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3071 advisory
- https://access.redhat.com/errata/RHSA-2023:7676 advisory
- https://security.netapp.com/advisory/ntap-20240125-0004/ advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0106.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0106 advisory
- https://www.oracle.com/security-alerts/cpujan2024.html#AppendixCGBU advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0277.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0277 advisory
…and 10 more