Lucene search

K
ibmIBM126FB45B392DB65322B47EEB27768E7F324E213DAB7ACFDC17F295724052BCC3
HistoryFeb 05, 2020 - 12:09 a.m.

Security Bulletin: Multiple vulnerabilities in Node.js affect IBM Rational Application Developer for WebSphere Software

2020-02-0500:09:48
www.ibm.com
11

EPSS

0.009

Percentile

82.5%

Summary

Multiple Node.js vulnerabilities has been discovered that affects the Cordova platform packaged with Rational Application Developer

Vulnerability Details

CVEID: CVE-2017-1000381**
DESCRIPTION:** c-ares could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read in the ares_parse_naptr_reply() function when parsing NAPTR responses. By sending specially crafted DNS response packet, an attacker could exploit this vulnerability to read memory outside of the given input buffer and cause a denial of service.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128625for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)



CVEID: CVE-2017-11499**
DESCRIPTION:** Node.js is vulnerable to a denial of service, caused by a flaw related to constant HashTable seeds. A remote attacker could exploit this vulnerability to flood the hash and cause a denial of service.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/129465for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM Rational Application Developer for WebSphere Software v9.1, v9.5, and v9.6

Remediation/Fixes

Update the IBM SDK for Node.js using by the Cordova platform in the product to address this vulnerability:

Product VRMF APAR Remediation/First Fix
Rational Application Developer 9.1.x PI87859 Apply the following fixes:

Then update Node.js by applying IBM SDK for Node.js Version 6 release updated equivalent to Joyent Node.js API version 6.11.2 to the Cordova platform in the product

Installation instructions for applying the update to the Cordova platform in the product can be found here:

Upgrading the IBM SDK for Node.js used by Cordova

Rational Application Developer| 9.5.x| PI87859| Apply the following fixes:

Then update Node.js by applying IBM SDK for Node.js Version 6 release updated equivalent to Joyent Node.js API version 6.11.2 to the Cordova platform in the product

Installation instructions for applying the update to the Cordova platform in the product can be found here:

Upgrading the IBM SDK for Node.js used by Cordova

Rational Application Developer| 9.6.x| PI87859| Apply IBM SDK for Node.js Version 6 release updated equivalent to Joyent Node.js API version 6.11.2 to the Cordova platform in the product

Installation instructions for applying the update to the Cordova platform in the product can be found here:

Upgrading the IBM SDK for Node.js used by Cordova

Workarounds and Mitigations

None