Lucene search

K
ibmIBM2B92C36DF570DFCF122A332D3B088AA29C2D5337205B90FE12EF9BEC6ED40D72
HistoryAug 13, 2019 - 9:02 p.m.

Security Bulletin: API Connect V2018 is impacted by vulnerabilities in golang (CVE-2019-11841)

2019-08-1321:02:31
www.ibm.com
8

EPSS

0.007

Percentile

80.8%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-11841
**DESCRIPTION:*Golang could allow a remote attacker to conduct spoofing attacks, caused by a flaw in the clearsign package of supplementary Go cryptography libraries. An attacker could exploit this vulnerability to spoof the messages.
CVSS Base Score: 5.9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/160985&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected IBM API Management Affected Versions
IBM API Connect 2018.1-2018.4.1.6

Remediation/Fixes

Affected releases Fixed in VRMF APAR Remediation / First Fix
IBM API Connect V2018.1-2018.4.1.6 2018.4.1.7 fixpack

LI81006

|

Addressed in IBM API Connect v2018.4.1.7 fixpack.

Management server is impacted.

Follow this link and find the โ€œmanagementโ€ package appropriate for form factor for your installation for 2018.4.1.7.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.6&platform=All&function=all&source=fc

Workarounds and Mitigations

None

EPSS

0.007

Percentile

80.8%

Related for 2B92C36DF570DFCF122A332D3B088AA29C2D5337205B90FE12EF9BEC6ED40D72