Lucene search

K
ibmIBM1B6D11DC10417D496C2E94388C3A9A396D89766208E498043F0ED1AEB3FA3388
HistoryNov 11, 2021 - 10:12 a.m.

Security Bulletin: Vulnerabilities in Node.js affect IBM Integration Bus v10 (CVE-2021-32804)

2021-11-1110:12:01
www.ibm.com
15
ibm
integration bus
node.js
vulnerability
fix
cve-2021-32804
linux
windows

EPSS

0.007

Percentile

80.2%

Summary

IBM Integration Bus ship with Node.js for which vulnerabilities were reported and have been addressed. Vulnerability details are listed below.

Vulnerability Details

CVEID:CVE-2021-32804
**DESCRIPTION:**Node.js tar module could allow a local attacker to traverse directories on the system, caused by insufficient absolute path sanitization. An attacker could use a specially-crafted tar file containing “dot dot” sequences (/…/) to create or overwrite arbitrary files on the system.
CVSS Base score: 8.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/206719 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)

Affected Products and Versions

IBM Integration Bus V10 , V10.0.0.0 - V10.0.0.24 ( Linux on Intel x86-64 and Windows 64-bit only)

Remediation/Fixes

Product

|

VRMF

| APAR|

Remediation / Fix

—|—|—|—
IBM Integration Bus
| V10.0.0.0-V10.0.0.24| IT38593| Interim fix for APAR (IT38663) is available from

IBM Fix Central

Workarounds and Mitigations

None