Lucene search

K
ibmIBM1DE804649D0EB8A7B0D6A24390B9343527F44D0500F111E7C60592EDC4693B2A
HistorySep 14, 2021 - 1:37 p.m.

Security Bulletin: IBM App Connect Enterprise Certified Container may be vulnerable to Denial of Service via CVE-2021-33196

2021-09-1413:37:44
www.ibm.com
15
ibm
app connect enterprise
vulnerability
denial of service
cve-2021-33196
operator
ace server
upgrade

EPSS

0.003

Percentile

65.7%

Summary

IBM App Connect Enterprise Certified Container may be vulnerable to Denial of Service via CVE-2021-33196. This affects the Operator itself and the ACE server image

Vulnerability Details

CVEID:CVE-2021-33196
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw in the NewReader and OpenReader functions in archive/zip. By persuading a victim to open a specially-crafted archive file, a remote attacker could exploit this vulnerability to cause a panic or an unrecoverable fatal error, and results in a denial of service condition.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/206602 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Enterprise Certified Container 1.0 with Operator
App Connect Enterprise Certified Container 1.1 with Operator
App Connect Enterprise Certified Container 1.2 with Operator
App Connect Enterprise Certified Container 1.3 with Operator
App Connect Enterprise Certified Container 1.4 with Operator
App Connect Enterprise Certified Container 1.5 with Operator

Remediation/Fixes

App Connect Enterprise Certified Container 1.0, 1.2, 1.3, 1.4 and 1.5 CD

Upgrade to App Connect Enterprise Certified Container Operator version 1.5.2 (available in CASE 1.5.2) or higher, and ensure that all Integration Server components are at 12.0.1.0-r3 or higher.

App Connect Enterprise Certified Container 1.1 LTS

Upgrade to App Connect Enterprise Certified Container Operator version 1.1.3 EUS (available in CASE 1.1.3) or higher, and ensure that all Integration Server components are at 11.0.0.13-r2-eus or higher.

Workarounds and Mitigations

None