IBM App Connect Enterprise Certified Container may be vulnerable to Denial of Service via CVE-2021-34558. This affects the Operator itself and the ACE server image
CVEID:CVE-2021-34558
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by the failure to properly assert that the type of public key in an X.509 certificate matches the expected type in the crypto/tls package. By persuading a victim to connect to a specially-crafted TLS server, a remote attacker could exploit this vulnerability to cause a TLS client to panic.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/205578 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
App Connect Enterprise Certified Container | 1.0 with Operator |
App Connect Enterprise Certified Container | 1.1 with Operator |
App Connect Enterprise Certified Container | 1.2 with Operator |
App Connect Enterprise Certified Container | 1.3 with Operator |
App Connect Enterprise Certified Container | 1.4 with Operator |
App Connect Enterprise Certified Container | 1.5 with Operator |
App Connect Enterprise Certified Container 1.0, 1.2, 1.3, 1.4 and 1.5 CD
Upgrade to App Connect Enterprise Certified Container Operator version 1.5.2 (available in CASE 1.5.2) or higher, and ensure that all Integration Server components are at 12.0.1.0-r3 or higher.
App Connect Enterprise Certified Container 1.1 LTS
Upgrade to App Connect Enterprise Certified Container Operator version 1.1.3 EUS (available in CASE 1.1.3) or higher, and ensure that all Integration Server components are at 11.0.0.13-r2-eus or higher.
None