Lucene search

K
ibmIBM612630C76F745039953454FE00A1CCB99B7D48AD1BAAC59BE8F1BB81C5357986
HistoryJun 30, 2021 - 5:54 p.m.

Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in Go

2021-06-3017:54:09
www.ibm.com
16
ibm watson discovery
ibm cloud pak for data
vulnerability
cve-2021-3114
cve-2021-3115
golang
command injection
remote code execution
upgrade
patch

EPSS

0.017

Percentile

87.9%

Summary

IBM Watson Discovery for IBM Cloud Pak for Data contains a vulnerable version of Go.

Vulnerability Details

CVEID:CVE-2021-3114
**DESCRIPTION:**An unspecified error with the P224() Curve implementation can generate incorrect outputs in Golang Go has an unknown impact and attack vector.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195677 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2021-3115
**DESCRIPTION:**Golang Go could allow a remote attacker to execute arbitrary code on the system, caused by a command injection flaw when using the go get command to fetch modules that make use of cgo. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195678 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ICP - Discovery 2.0.0-2.2.1

Remediation/Fixes

Upgrade to IBM Watson Discovery 2.2.1 and apply modeltrain-classic-1.0.2-patch-1

<https://cloud.ibm.com/docs/discovery-data?topic=discovery-data-install&gt;

<https://www.ibm.com/docs/en/cloud-paks/cp-data/3.5.0?topic=installing-applying-patches&gt;

Workarounds and Mitigations

None