IBM API Connect has addressed the following vulnerability.
CVEID:CVE-2021-23017
**DESCRIPTION:**NGINX could allow a remote attacker to execute arbitrary code on the system, caused by an off-by-one error in ngx_resolver_copy() while processing DNS responses. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.1
CVSS Temporal Score: See: <https://exchange.xforce.ibmcloud.com/vulnerabilities/202450> for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
API Connect | IBM API Connect V5.0.0.0-5.0.8.11 |
Affected Product | Addressed in VRMF | APAR | Remediation/First Fix |
---|
IBM API Connect
V5.0.0.0-V5.0.8.11
| 5.0.8.12|
LI82294
|
Addressed in IBM API Connect V5.0.8.12
Developer Portal is impacted.
Follow this link and find the “Portal” package.
http://www.ibm.com/support/fixcentral/swg/quickorder
None