Lucene search

K
ibmIBM19E39A755865FEB54142F6B8F38AFB6BC8A149FB5D8FB18F5A3FEC41C127B75E
HistoryNov 09, 2021 - 5:59 p.m.

Security Bulletin: A security vulnerability in Node.js affects IBM Cloud Pak for Multicloud Management Infrastructure Management and Managed Services

2021-11-0917:59:09
www.ibm.com
17
node.js
ibm cloud pak
multicloud management
infrastructure management
managed services
cve-2021-22939
remote attacker
security restrictions
https api
expired certificate
cvss base score
cvss temporal score
ibm cloud pak version 2.3.x fix pack 2
upgrade instructions

EPSS

0.011

Percentile

84.5%

Summary

A security vulnerability in Node.js affects IBM Cloud Pak for Multicloud Management Infrastructure Management and Managed Services.

Vulnerability Details

CVEID:CVE-2021-22939
**DESCRIPTION:**Node.js could allow a remote attacker to bypass security restrictions. If the https API was used incorrectly and “undefined” was in passed for the “rejectUnauthorized” parameter, an attacker could exploit this vulnerability to connect to servers using an expired certificate.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/207233 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3.x Fix Pack 2 by following the instructions at <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=upgrade-upgrading-fix-pack-2.&gt;

Workarounds and Mitigations

None