Lucene search

K
ibmIBM682BE4EA2492DA5D8B3BAF25DC1C2ABF3BE889367EFE7D646F66F8EAC16D549C
HistoryMay 28, 2021 - 7:22 p.m.

Security Bulletin: Multiple Security Vulnerabilities have been resolved in IBM Application Gateway (CVE-2021-20576, CVE-2021-20575, CVE-2021-29665)

2021-05-2819:22:00
www.ibm.com
8
ibm application gateway
security vulnerabilities
remote attacker
http get request
local storage
buffer overflow
sensitive information disclosure
docker store

EPSS

0.001

Percentile

41.3%

Summary

Multiple Security vulnerabilities have been fixed in the IBM Application Gateway product.

Vulnerability Details

CVEID:CVE-2021-20576
**DESCRIPTION:**IBM Application Gateway could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199280 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2021-20575
**DESCRIPTION:**IBM Application Gateway allows web pages to be stored locally which can be read by another user on the system.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199278 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2021-29665
**DESCRIPTION:**IBM Application Gateway is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.
CVSS Base score: 9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199399 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

**Third Party Entry:**199398
**DESCRIPTION:**IBM Application Gateway could disclose sensitive information in HTTP server headers that could be used in further attacks against the system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199398 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Application Gateway 1.0

Remediation/Fixes

Fixes for IBM Application Gateway can be downloaded from the ibmcom Docker store.

docker pull ibmcom/ibm-application-gateway:21.04

Workarounds and Mitigations

None

EPSS

0.001

Percentile

41.3%

Related for 682BE4EA2492DA5D8B3BAF25DC1C2ABF3BE889367EFE7D646F66F8EAC16D549C