Lucene search

K
ibmIBMDEBC899D5E7F52BAC830D06EFF16A64417FA7A826DA06C927EAAEEF2964D3F82
HistoryJun 08, 2021 - 10:33 p.m.

Security Bulletin: IBM DataPower Gateway may allow a potential DoS when importing malicious ZIP files (CVE-2019-13232)

2021-06-0822:33:53
www.ibm.com
43
ibm
datapower gateway
dos
vulnerability
zip files
cve-2019-13232

EPSS

0.001

Percentile

33.2%

Summary

IBM has addressed CVE-2019-13232

Vulnerability Details

CVEID:CVE-2019-13232
**DESCRIPTION:**Info-ZIP UnZip is vulnerable to a denial of service, caused by mishandling the overlapping of files inside a ZIP container. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause resource consumption.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/166873 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 2018.4.1.0-2018.4.1.12

Remediation/Fixes

Affected Product(s) Fixed in Version APAR
IBM DataPower Gateway 2018.4.1.13 IT32966

Workarounds and Mitigations

None