Lucene search

K
ibmIBM210C1B395D2C190643C8D57D696D151C878955A800CCF36EC759F762B5DEE1DB
HistorySep 27, 2020 - 6:26 p.m.

Security Bulletin: IBM Cloud Private is vulnerable to a MongoDB vulnerability (CVE-2020-7921)

2020-09-2718:26:07
www.ibm.com
10

0.001 Low

EPSS

Percentile

22.7%

Summary

IBM Cloud Private is vulnerable to a MongoDB vulnerability

Vulnerability Details

CVEID:CVE-2020-7921
**DESCRIPTION:**MongoDB Server could allow a remote authenticated attacker to bypass security restrictions, caused by improper serialization of internal state in the authorization subsystem. An attacker could exploit this vulnerability to bypass IP allowlisting protection.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/181688 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Private 3.2.1 CD
IBM Cloud Private 3.2.2 CD

Remediation/Fixes

Product defect fixes and security updates are only available for the two most recent Continuous Delivery (CD) update packages

  • IBM Cloud Private 3.2.1
  • IBM Cloud Private 3.2.2

For IBM Cloud Private 3.2.1, apply Aug fix pack:

For IBM Cloud Private 3.2.2, apply Aug fix pack:

For IBM Cloud Private 3.1.0, 3.1.1, 3.1.2, 3.2.0:

Upgrade to the latest Continuous Delivery (CD) update package, IBM Cloud Private 3.2.2.2008.

If required, individual product fixes can be made available between CD update packages for resolution of problems. Contact IBM support for assistance

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

22.7%

Related for 210C1B395D2C190643C8D57D696D151C878955A800CCF36EC759F762B5DEE1DB