Lucene search

K
ibmIBM315B599BAD4F5791931A11CFCD6DB5DF8F628F9EED8F69A67AF98E8B3CA6C1BC
HistoryJun 20, 2022 - 4:18 p.m.

Security Bulletin: Flaw in Go may affect DataPower Operator (CVE-2021-44717)

2022-06-2016:18:48
www.ibm.com
16

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

68.7%

Summary

IBM has addressed the CVE

Vulnerability Details

CVEID:CVE-2021-44717
**DESCRIPTION:**Golang Go could allow a remote attacker to bypass security restrictions, caused by an error in the syscall.ForkExec() interface. By causing the erroneous closing of file descriptor 0 after file-descriptor exhaustion, an attacker could exploit this vulnerability to compromise data integrity and/or confidentiality in a somewhat uncontrolled way in programs linked with and using syscall.ForkExec().
CVSS Base score: 4.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/216563 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
DataPower Operator 1.2 1.2.0-1.2.6
DataPower Operator 1.5 1.5.0

Remediation/Fixes

Affected product Fixed in version Release notes
DataPower Operator 1.2 1.2.7 <https://ibm.github.io/datapower-operator-doc/release-notes/eus/&gt;
DataPower Operator 1.5 1.5.1 <https://ibm.github.io/datapower-operator-doc/release-notes/cd/&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdatapower_gatewayMatch1.2
OR
ibmdatapower_gatewayMatch1.5

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

68.7%