IBM App Connect Enterprise Certified Container may be vulnerable to arbitrary code execution via CVE-2021-23440. This only affects App Connect Dashboards
CVEID:CVE-2021-23440
**DESCRIPTION:**Nodejs set-value module could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 7.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/209431 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Affected Product(s) | Version(s) |
---|---|
App Connect Enterprise Certified Container | 1.0 with Operator |
App Connect Enterprise Certified Container | 1.1 with Operator |
App Connect Enterprise Certified Container | 1.2 with Operator |
App Connect Enterprise Certified Container 1.0 and 1.2
Upgrade to App Connect Enterprise Certified Container Operator version 1.3.0 (available in CASE 1.3.0) or higher, and ensure that all Dashboard components are at 11.0.0.11-r2 or higher.
App Connect Enterprise Certified Container 1.1 LTS
Upgrade to App Connect Enterprise Certified Container Operator version 1.1.1 EUS (available in CASE 1.1.1) or higher, and ensure that all Dashboard components are at 11.0.0.12-r1-eus or higher.
None