Lucene search

K
ibmIBM5BAB925D00506519EAB6BD95E6F67737E30792E112133E8A0E3B57C3A0B3F343
HistoryJun 11, 2020 - 4:21 p.m.

Security Bulletin: IBM Event Streams is affected by multiple Node.js vulnerabilities

2020-06-1116:21:21
www.ibm.com
13

0.011 Low

EPSS

Percentile

84.9%

Summary

IBM Event Streams is affected by the following vulnerabilities in the included Node.js runtime shipped.

Vulnerability Details

CVEID:CVE-2019-10795
**DESCRIPTION:**Node.js undefsafe module could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176422 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-10791
**DESCRIPTION:**Node.js promise-probe module could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the file, outputFile and options functions. By sending specially-crafted arguments, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176417 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-10794
**DESCRIPTION:**Node.js component-flatten module could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176421 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-10788
**DESCRIPTION:**Node.js im-metadata module could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the exec argument. By sending specially-crafted arguments, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176416 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-10793
**DESCRIPTION:**Node.js dot-object module could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176420 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-10787
**DESCRIPTION:**Node.js im-resize module could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the cmd argument in index.js. By sending specially-crafted arguments, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176415 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-10786
**DESCRIPTION:**Node.js network-manager module could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the execSync() argument. By sending specially-crafted arguments, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176413 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-10792
**DESCRIPTION:**Node.js bodymen module could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176418 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 2019.2.1
IBM Event Streams in IBM Cloud Pak for Integration 2019.2.2
IBM Event Streams in IBM Cloud Pak for Integration 2019.2.3
IBM Event Streams 2019.4.1
IBM Event Streams in IBM Cloud Pak for Integration 2019.4.1

Remediation/Fixes

Upgrade from IBM Event Streams 2019.2.1 to IBM Event Streams 2019.4.1 by downloading IBM Event Streams 2019.4.1 from IBM Passport Advantage.

Upgrade from IBM Event Streams 2019.4.1 to the latest Fix Pack.

Upgrade IBM Event Streams 2019.2.2, IBM Event Streams 2019.2.3 and IBM Event Streams 2019.4.1 in IBM Cloud Pak for Integration by downloading IBM Event Streams 2019.4.2 in IBM Cloud Pak for Integration 2020.2.1 from IBM Passport Advantage.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm event streamseqany

0.011 Low

EPSS

Percentile

84.9%

Related for 5BAB925D00506519EAB6BD95E6F67737E30792E112133E8A0E3B57C3A0B3F343