Lucene search

K
ibmIBME51AD2501331015E7E19A3AC49A96E1AC1A7C291EEE9E468031B3BA17AE28285
HistoryMay 31, 2019 - 1:40 p.m.

Security Bulletin: IBM API Connect's Developer Portal is impacted by vulnerabilities in Drupal core (CVE-2019-10909 CVE-2019-10910 CVE-2019-10911 CVE-2019-11358)

2019-05-3113:40:01
www.ibm.com
10

0.035 Low

EPSS

Percentile

91.6%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-10911
**DESCRIPTION:*Drupal core could allow a remote attacker to bypass security restrictions, caused by a flaw in the cookie management. By using a specially-crafted cookie, an attacker could exploit this vulnerability to bypass access restrictions.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159639&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2019-10910
**DESCRIPTION:*Drupal core could allow a remote attacker to execute arbitrary code on the system, caused by improper validation of user-supplied input. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159638&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-10909
**DESCRIPTION:*Drupal core is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the PHP templating engine. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base Score: 6.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159637&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

CVEID:CVE-2019-11358
**DESCRIPTION:*Drupal core is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the jQuery. A remote authenticated attacker could exploit this vulnerability to execute script in a victim’s Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base Score: 5.4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159633&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM API Connect v2018.1-2018.4.1.4
IBM API Connect v5.0.0.0-5.0.8.6

Remediation/Fixes

Affected Product Addressed in VRMF APAR Remediation/First Fix

IBM API Connect

V2018.1-2018.4.1.4

| 2018.4.1.5 | LI80880 |

Addressed in IBM API Connect v2018.4.1.5 fixpack.

Developer Portal is impacted.

Follow this link and find the “portal” package appropriate for the form factor of your installation:** **

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.4&platform=All&function=all&source=fc

IBM API Connect

V5.0.0.0-5.0.8.6

| 5.0.8.6 iFix |

LI80880

|

Addressed in IBM API Connect 5.0.8.6 iFix.

Follow this link and find the portal package suitable for the form factor of your installation.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.8.5&platform=All&function=fixId&fixids=5.0.8.6-iFix-APIConnect-Portal-Ubuntu16-20190423-2319.ova%3A67094276418854,5.0.8.6-iFix-APIConnect-Portal-Ubuntu16-20190423-2319%3A67094276418854&includeSupersedes=0&source=fc

Workarounds and Mitigations

None