Lucene search

K
ibmIBMAE422B9F3EF2D38F564DFC656E71F38129E00A45907005EE5EA7A634892D0C9C
HistoryMay 18, 2021 - 1:25 p.m.

Security Bulletin: Security vulnerabilities in Go affect IBM Cloud Pak for Multicloud Management Hybrid GRC

2021-05-1813:25:41
www.ibm.com
20
ibm cloud pak
multicloud management
security vulnerabilities
go
grc
cve-2021-3114
cve-2021-3115
upgrade

EPSS

0.017

Percentile

87.9%

Summary

Security Bulletin: Security vulnerabilities in Go affect IBM Cloud Pak for Multicloud Management Hybrid GRC.

Vulnerability Details

CVEID:CVE-2021-3114
**DESCRIPTION:**An unspecified error with the P224() Curve implementation can generate incorrect outputs in Golang Go has an unknown impact and attack vector.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195677 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2021-3115
**DESCRIPTION:**Golang Go could allow a remote attacker to execute arbitrary code on the system, caused by a command injection flaw when using the go get command to fetch modules that make use of cgo. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195678 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Security Services 2.0
IBM Cloud Pak for Multicloud Management Security Services 2.1
IBM Cloud Pak for Multicloud Management Security Services 2.2

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3 by following the instructions in <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=installation-upgrade&gt;

Workarounds and Mitigations

None