IBM API Connect had addressed the following vulnerability.
CVEID:CVE-2019-11048
**DESCRIPTION:**PHP is vulnerable to a denial of service, caused by a flaw in the php-src/main/rfc1867.c. By uploading a specially crafted file, a remote attacker could exploit this vulnerability to cause accumulation of uncleaned temporary files to exhaust the disk space on the target server.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182427 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
API Connect | IBM API Connect V5.0.0.0-5.0.8.8 |
Affected Product
|
Addressed in VRMF
|
APAR
|
Remediation / First Fix
—|—|—|—
IBM API Connect
V5.0.0.0-5.0.8.8
|
5.0.8.8 iFix released on June 18, 2020 or later
| LI81613| Addressed in IBM API Connect V5.0.8.8 iFix
released on June 18, 2020 or later
Developer Portal is impacted.
Follow this link and find the “Portal” package:
http://www.ibm.com/support/fixcentral/swg/quickorder
None