Lucene search

K
ibmIBM56F736C514D801D48076A768942C738445DEA5EC6AD9001D0E68FF2BEA3431CB
HistoryMay 03, 2021 - 3:16 p.m.

Security Bulletin: Go is vulnerable to a denial of service on IBM Watson Machine Learning on CP4D

2021-05-0315:16:23
www.ibm.com
6

0.011 Low

EPSS

Percentile

84.4%

Summary

Golang Go is vulnerable to a denial of service and bypass security restrictions on IBM Watson Machine Learning on CP4D

Vulnerability Details

CVEID:CVE-2020-15586
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a data race in some net/http servers. By sending specially-crafted HTTP requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185446 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2020-14039
**DESCRIPTION:**Go could allow a remote attacker to bypass security restrictions, caused by improper validation on the VerifyOptions.KeyUsages EKU requirements during the X.509 certificate verification. An attacker could exploit this vulnerability to gain access to the system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185443 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Machine Learning on CP4D 2.5,3.0

Remediation/Fixes

Fix is available on IBM Watson Machine Learning on CP4D 3.5
Patches are available here : <https://www.ibm.com/support/pages/node/5693732&gt;

Workarounds and Mitigations

None