Summary Security vulnerabilities are addressed with IBM Business Automation Insights 23.0.2-IF001. Vulnerability Details ** CVEID: CVE-2023-46673 DESCRIPTION: **Elastic Elasticsearch is vulnerable to a denial of service, caused by improper handling of exceptional conditions. By sending a specially crafted request using the Simulate Pipeline API, a remote authenticated attacker could exploit this vulnerability to cause an Elasticsearch node to crash. CVSS Base score: 6.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/272207 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM Business Automation Insights| 23.0.2 Remediation/Fixes IBM strongly recommends addressing the vulnerability now. Product(s)| Version(s) number and/or range | Remediation/Fix/Instructions —|—|— IBM Business Automation Insights| 23.0.2| Apply security fix 23.0.2-IF001 or above Workarounds and Mitigations…Read More
References
Back to Main