IBM App Connect Enterprise v11 & v12 ships with Node.js for which vulnerabilities were reported and have been addressed. Vulnerability details are listed below.
CVEID:CVE-2021-22918
**DESCRIPTION:**Node.js is vulnerable to a denial of service, caused by an out-of-bounds read in the libuvโs uv__idna_toascii() function. By invoking the function using dns moduleโs lookup() function, a remote attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/204784 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
CVEID:CVE-2021-22921
**DESCRIPTION:**Node.js could allow a local attacker to gain elevated privileges on the system, caused by improper configuration of permissions in the installation directory. Under certain conditions. An attacker could exploit this vulnerability to perform PATH and DLL hijacking attacks.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/204785 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
IBM App connect Enterprise V11 , V11.0.0.0 - V11.0.0.13
IBM App connect Enterprise V12.0.1.0
Product
|
VRMF
| APAR|
Remediation / Fix
โ|โ|โ|โ
IBM App connect Enterprise V11
| V11.0.0.0-V11.0.0.13| IT38520
|
The APAR is available in fix pack 11.0.0.14
IBM App connect Enterprise V12
| V12.0.1.0
| IT38520
|
The APAR is available in fix pack 12.0.2.0
None