Lucene search

K
ibmIBMDA2EED2B0475D138CCA1BAE01157F3CFA6C1C284092799EA42A78A5B89EC994D
HistoryFeb 19, 2021 - 5:07 a.m.

Security Bulletin: A security vulnerability in Node.js y18n module affects IBM Cloud Pak for Multicloud Management.

2021-02-1905:07:57
www.ibm.com
7

0.304 Low

EPSS

Percentile

97.0%

Summary

A security vulnerability in Node.js y18n module affects IBM Cloud Pak for Multicloud Management.

Vulnerability Details

CVEID:CVE-2020-7774
**DESCRIPTION:**Node.js y18n module could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 7.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191999 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.2 latest fixpack by following the instructions in <https://www.ibm.com/support/knowledgecenter/en/SSFC4F_2.2.0/install/upgrade.html.&gt;

Workarounds and Mitigations

None