Lucene search

K
ibmIBM561973306D4E4BEA7464F4573BB21D13B8BBB6C67C418A509CAF83B7E7F658F1
HistoryJul 11, 2023 - 11:31 a.m.

Security Bulletin: Vulnerability of System.Text.Encodings.Web.4.5.0 .dll has afftected to .NET Agent

2023-07-1111:31:57
www.ibm.com
21
.net agent
system.text.encodings.web.4.5.0
cve-2021-26701
remote code execution
update
apm agents
monitoring

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.081

Percentile

94.3%

Summary

.NET Agent is vulnerable to System.Text.Encodings.Web.4.5.0 .dll . [CVE-2021-26701] This fix includes System.Text.Encodings.Web.7.0.0 upgraded to System.Text.Encodings.Web.4.5.0 .dll.

Vulnerability Details

CVEID:CVE-2021-26701
**DESCRIPTION:**Microsoft .NET Core and Visual Studio could allow a remote attacker to execute arbitrary code on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system with elevated privileges.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196358 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
APM Agents for Monitoring all

Remediation/Fixes

.NET Agent release 8.1.4.0.20 (.NET Agent Version: 08.23.05.00)

Download the APM Advanced Agents installer from Passport Advantage. Please refer below link for download instructions:

<https://www.ibm.com/docs/en/capmp/8.1.4?topic=advantage-part-numbers&gt;

Part Number : M0CLJML

Build Name : adv_agents_win_8.1.4.0.20.zip

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_composite_application_manager_for_wesbsphereMatch814020
VendorProductVersionCPE
ibmtivoli_composite_application_manager_for_wesbsphere814020cpe:2.3:a:ibm:tivoli_composite_application_manager_for_wesbsphere:814020:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.081

Percentile

94.3%