Lucene search

K
ibmIBM3D3C4FB3DC4BEAFAD73308AFB9445F4931AF1CAA76C3F7953545A147535F56AC
HistoryFeb 19, 2021 - 5:10 a.m.

Security Bulletin: A security vulnerability in Node.js affects IBM Cloud Pak for Multicloud Management.

2021-02-1905:10:17
www.ibm.com
8
node.js
ibm cloud pak
multicloud management
denial of service
vulnerability
security vulnerability
cve-2020-8277
dns request
upgrade
fixpack

EPSS

0.007

Percentile

81.1%

Summary

A security vulnerability in Node.js affects IBM Cloud Pak for Multicloud Management.

Vulnerability Details

CVEID:CVE-2020-8277
**DESCRIPTION:**Node.js is vulnerable to a denial of service. By getting the application to resolve a DNS record with a larger number of responses, an attacker could exploit this vulnerability to trigger a DNS request for a host of their choice resulting in a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191755 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.2 latest fixpack by following the instructions in <https://www.ibm.com/support/knowledgecenter/en/SSFC4F_2.2.0/install/upgrade.html.&gt;

Workarounds and Mitigations

None