Lucene search

K
ibmIBMA18D2141602AC8094E093D3F9CA3B593758A5DE5F31EB35D8700CDD1D1536988
HistoryJun 15, 2018 - 7:06 a.m.

Security Bulletin: Multiple vulnerabilities affecting web servers that run code in a CGI or CGI-like context affects IBM API Connect (CVE-2016-5385, CVE-2016-1000105)

2018-06-1507:06:31
www.ibm.com
15

EPSS

0.928

Percentile

99.1%

Summary

IBM API Connect is affected by multiple vulnerabilities relating to web servers that run code in a CGI or CGI-like context (CVE-2016-5385, CVE-2016-1000105). IBM has addressed these vulnerabilities.

Vulnerability Details

CVEID: CVE-2016-5385**
DESCRIPTION:** PHP could allow a remote attacker to redirect HTTP traffic of CGI application, caused by the failure to protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable. By using a specially-crafted Proxy header in a HTTP request, an attacker could exploit this vulnerability to redirect outbound HTTP traffic to arbitrary proxy server. This is also known as the “HTTPOXY” vulnerability.
CVSS Base Score: 8.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115088 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2016-1000105**
DESCRIPTION:** nginx could allow a remote attacker to redirect HTTP traffic of CGI application, caused by the failure to protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable. By using a specially-crafted Proxy header in a HTTP request, an attacker could exploit this vulnerability to redirect outbound HTTP traffic to arbitrary proxy server. This is also known as the “HTTPOXY” vulnerability.
CVSS Base Score: 8.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115603 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM API Connect V5.0.x

Remediation/Fixes

Product

| VRMF|APAR|Remediation/First Fix
—|—|—|—
IBM API Connect| 5.0.x| LI79350| <http://www-01.ibm.com/support/docview.wss?uid=swg21990227&gt;

Workarounds and Mitigations

None