PT-2023-9007 · Ibm · Ibm Infosphere Information Server
Paweł Żurek
·
Published
2023-05-19
·
Updated
2023-05-26
·
CVE-2023-32336
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Information Server version 11.7
Description
The issue is related to the restoration of untrusted data in memory in the RMI service of the InfoSphere Information Server platform, which can lead to remote code execution. This allows a remote attacker to execute arbitrary code due to insecure deserialization in the RMI service.
Recommendations
For IBM InfoSphere Information Server version 11.7, consider disabling the RMI service as a temporary workaround until a patch is available. Restrict access to the RMI service to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Infosphere Information Server