Platform Navigator and Automation Assets in IBM Cloud Pak for Integration are vulnerable to denial of service due to Go (CVE CVE-2021-41771 & CVE-2021-41772) with details below
CVEID:CVE-2021-41772
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by an out-of-bounds slice situation in the Reader.Open function. By using a specially-crafted ZIP archive containing an invalid name or an empty filename field, a remote attacker could exploit this vulnerability to cause a panic, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213019 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID:CVE-2021-41771
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by an out-of-bounds slice situation in the ImportedSymbols function in debug/macho. By using specially-crafted binaries, a remote attacker could exploit this vulnerability to cause a panic, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213016 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
Platform Navigator in IBM Cloud Pak for Integration (CP4I) | 2020.4.1 |
2021.1.1 | |
2021.2.1 | |
2021.3.1 | |
Automation Assets in IBM Cloud Pak for Integration (CP4I) | 2020.4.1 |
2021.1.1 | |
2021.2.1 |
Platform Navigator 2020.4.1 in****IBM Cloud Pak for Integration
Upgrade Platform Navigator 2020.4.1 to 2020.4.1-5-eus using the Operator upgrade process described in the IBM Documentation
<https://www.ibm.com/docs/en/cloud-paks/cp-integration/2020.4?topic=202041-upgrading-platform-navigator-component-deployment-interface>
Platform Navigator version 2021.1, 2021.2, or 2021.3 in IBM Cloud Pak for Integration
Upgrade Platform Navigator to 2021.4.1 using the Operator upgrade process described in the IBM Documentation
**
Asset Repository version 2020.4.1 in IBM Cloud Pak for Integration**
Upgrade Asset Repository to 2020.4.1-4-eus using the Operator upgrade process described in the IBM Documentation
Asset Repository version 2021.1 or 2021.2 in IBM Cloud Pak for Integration
Upgrade Asset Repository to 2021.4.1-2 using the Operator upgrade process described in the IBM Documentation
None