Lucene search

K
ibmIBM4C279F93EC199C802593E90AE4CC2A4ED547BF5489382789B60D31AAA0663262
HistorySep 26, 2024 - 12:16 p.m.

Security Bulletin: IBM App Connect Enterprise are vulnerable to a denial of service due to node.js expressjs body-parser module. (CVE-2024-45590)

2024-09-2612:16:18
www.ibm.com
3
ibm app connect enterprise
denial of service
expressjs body-parser
cve-2024-45590
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

Summary

IBM App Connect Enterprise are vulnerable to a denial of service due to node.js expressjs body-parser module. (CVE-2024-45590). This bulletin identifies the steps to take to address the vulnerability.

Vulnerability Details

CVEID:CVE-2024-45590
**DESCRIPTION:**expressjs body-parser is vulnerable to a denial of service, caused by a flaw when url encoding is enabled. By sending a specially crafted payload, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/359790 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.12.5

Remediation/Fixes

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise

Affected Product(s)

|

Version(s)

|

APAR

|

Remediation / Fixes

—|—|—|—

IBM App Connect Enterprise

|

12.0.1.0 - 12.0.12.5

| IT46947 |

The APAR (IT46947) is available from

IBM App Connect Enterprise v12 - Fix Pack Release 12.0.12.6

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.12.5
VendorProductVersionCPE
ibmapp_connect_enterprise*cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

Related for 4C279F93EC199C802593E90AE4CC2A4ED547BF5489382789B60D31AAA0663262