Lucene search

K
ibmIBM9BCF9EB9E4FE0530005C16DD71B4C279664E4ADAF8E8A25A75DF51EE9FAE6943
HistoryApr 19, 2022 - 8:12 p.m.

Security Bulletin: IBM Security Guardium Insights is affected by Node.js vulnerability (CVE-2021-22939)

2022-04-1920:12:12
www.ibm.com
23
ibm security guardium insights
node.js vulnerability
cve-2021-22939
remote attacker
security restrictions
https api
expired certificate
cvss base score 3.7
update
version 3.1.5

EPSS

0.011

Percentile

84.5%

Summary

IBM Security Guardium Insights addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2021-22939
**DESCRIPTION:**Node.js could allow a remote attacker to bypass security restrictions. If the https API was used incorrectly and “undefined” was in passed for the “rejectUnauthorized” parameter, an attacker could exploit this vulnerability to connect to servers using an expired certificate.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/207233 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Guardium Insights 3.0

Remediation/Fixes

IBM encourages customers to update their systems promptly

Product

|

VRMF

|

Remediation / Fix

—|—|—
IBM Security Guardium Insights| 3.0|

Please download version 3.1.5

https://www.ibm.com/software/passportadvantage/?mhsrc=ibmsearch_a&mhq=pasport%20advantage

Workarounds and Mitigations

None