Lucene search

K
ibmIBM04B37F2D160D9D367D67DA8476D560DAFCDF7FF4A1B6F6726D3E08215C1BBDB7
HistoryAug 23, 2018 - 4:19 p.m.

Security Bulletin: IBM API Connect is impacted by a Drupal 8 vulnerability (CVE-2018-14773)

2018-08-2316:19:33
www.ibm.com
9

0.878 High

EPSS

Percentile

98.7%

Summary

IBM API Connect has fixed the following vulnerability.

API Connect is impacted by vulnerabilities addressed in the Drupal 8 advisory https://www.drupal.org/SA-CORE-2018-005

Vulnerability Details

CVEID:CVE-2018-14773
**DESCRIPTION:*Drupal Core could allow a remote attacker to bypass security restrictions, caused by an access control flaw in the 3rd party Symfony HttpFoundation component. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to bypass restrictions on higher level caches and web servers.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/147835&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product Affected Versions
API Connect 2018.1.0 - 2018.3.4

Remediation/Fixes

Product |

Addressed in VRMF

| APAR | Remediation / First Fix
β€”|β€”|β€”|β€”
API Connect | 2018.3.5 | LI80272 |

Addressed in IBM API Connect Developer Portal 2018.3.5

Follow this link and find the appropriate form factor for your installation: β€œportal-images-kubernetes” or β€œapicup” or β€œIBM_APIConnect_ICP” for 2018.3.5 or beyond.

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.3.4&platform=All&function=all

0.878 High

EPSS

Percentile

98.7%