Skip to main navigation Skip to main content Skip to page footer

OpenSSL component vulnerability

Security Advisories IBA-2022-05

Зеленый фон с круговым цифровым интерфейсным дизайном.
Publishing Date 2022-08-08
Last Update 2022-08-08
Tracking IDIBA-2022-05
CVECVE-2022-0778
CVSS Base Score7.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

A vulnerability in the OpenSSL component, which is used by Kafka in ibaPDA, could allow an attacker to create a denial of service (DoS) condition by creating a specially crafted certificate with elliptic curves.

Affected products

ibaPDA
All versions prior to v8.0.2

How do I know that I'm affected

Check the version number in the title of the status application on the system where the server is running.

Solution

Update to ibaPDA v8.0.2 or higher.

Customer Actions

Please update to ibaPDA v8.0.2 or higher.

Technical Details

Issue

The Kafka component used by ibaPDA used an older version of OpenSSL (1.1.1l) that was vulnerable to the above mentioned CVE-2022-0778. An attacker could have used a specially crafted certificate with elliptic curves to create a denial of service condition where a function would loop forever.

Timeline

2022-07-16Notified by iba A&C Team
2022-08-03New ibaPDA version released
2022-08-08Security advisory published
Вернуться к списку

Что бы Вы хотели сделать сегодня?

Выбрав страну, мой запрос будет направлен в страновое отделение iba AG, отвечающее за продажи и поддержку.Политика конфиденциальности