Lucene search

K
ibmIBM6EE64696FDA9665AA0F54B4FB93057230ED3464327A74367561AE8FE0E2653CA
HistoryJun 18, 2021 - 2:39 p.m.

Security Bulletin: IBM Cloud Pak for Integration is vulnerable to Node.js lodash vulnerability (CVE-2021-23337)

2021-06-1814:39:27
www.ibm.com
15
ibm cloud pak
node.js
lodash vulnerability
cve-2021-23337
command injection
cvss 7.2
platform navigator
upgrade
ibm documentation

EPSS

0.009

Percentile

82.6%

Summary

IBM Cloud Pak for Integration is vulnerable to lodash vulnerability CVE-2021-23337 with details below.

Vulnerability Details

CVEID:CVE-2021-23337
**DESCRIPTION:**Node.js lodash module could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a command injection flaw in the template. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196797 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Platform Navigator in IBM Cloud Pak for Integration (CP4I) 2020.4.1-0-eus
2020.4.1-1-eus

Remediation/Fixes

Platform Navigator in****IBM Cloud Pak for Integration

Upgrade Platform Navigator to 2020.4.1-2-eus using the Operator upgrade process described in the IBM Documentation
<https://www.ibm.com/docs/en/cloud-paks/cp-integration/2020.4?topic=202041-upgrading-platform-navigator-component-deployment-interface&gt;

Workarounds and Mitigations

None

EPSS

0.009

Percentile

82.6%

Related for 6EE64696FDA9665AA0F54B4FB93057230ED3464327A74367561AE8FE0E2653CA