Lucene search

K
ibmIBMBEBF8A07906A8F35FF3BC068026B3463B248B5C923B7DB769559C4DC6A31E015
HistoryMar 12, 2021 - 7:09 p.m.

Security Bulletin: Streams Flows might be affected by some underlying Node.js vulnerabilities

2021-03-1219:09:09
www.ibm.com
13

0.008 Low

EPSS

Percentile

81.2%

Summary

Streams Flows might be affected by some underlying Node.js vulnerabilities.

Vulnerability Details

CVEID:CVE-2020-8277
**DESCRIPTION:**Node.js is vulnerable to a denial of service. By getting the application to resolve a DNS record with a larger number of responses, an attacker could exploit this vulnerability to trigger a DNS request for a host of their choice resulting in a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191755 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

All versions.

Remediation/Fixes

Streams Flows has been discontinued. Please uninstall the Streams Flows feature to avoid any security issues.

Workarounds and Mitigations

Streams Flows has been discontinued. Please uninstall the Streams Flows feature to avoid any security issues.

CPENameOperatorVersion
ibm streamseq3.0