Lucene search

K
ibmIBM4242C683C007EE5B94B25809E80B1C728A4F2E637857CE565129C26B4FD05423
HistoryNov 16, 2021 - 7:52 p.m.

Security Bulletin: Multiple vulnerabilities affect IBM Rational® Application Developer for WebSphere® Software - September 2021

2021-11-1619:52:56
www.ibm.com
22

0.004 Low

EPSS

Percentile

72.0%

Summary

Vulnerabilities detected in Node.js versions before v14.16.2 affects IBM Rational® Application Developer for WebSphere® Software.

Vulnerability Details

CVEID:CVE-2021-3712
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read when processing ASN.1 strings. By sending specially crafted data, an attacker could exploit this vulnerability to read contents of memory on the system or perform a denial of service attack.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/208073 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

Rational® Application Developer for WebSphere® Software

|

9.6

—|—

Rational® Application Developer for WebSphere® Software

|

9.7

Remediation/Fixes

Available at Fix Central

http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FRational%2FIBM+Rational+Application+Developer+for+WebSphere+Software&fixids=Rational-RAD-PH40823Nodejs-ifix&source=SAR

Workarounds and Mitigations

None