Lucene search

K
ibmIBME54B91D137CC342A71B7C7C04AB3A40F78C9B5313B1B62814E6F49B8E3FC8D0D
HistoryNov 09, 2021 - 6:19 p.m.

Security Bulletin: A security vulnerability in NGINX affects IBM Cloud Pak for Multicloud Management Managed Services

2021-11-0918:19:49
www.ibm.com
16
nginx
ibm cloud pak
multicloud management
vulnerability
tls
cross-protocol
attack
security
upgrade

EPSS

0.001

Percentile

46.8%

Summary

A security vulnerability in NGINX affects IBM Cloud Pak for Multicloud Management Managed Services.

Vulnerability Details

CVEID:CVE-2021-3618
**DESCRIPTION:**Sendmail, vsftpd and NGINX could provide weaker than expected security, caused by an ALPACA (application layer protocol content confusion) attack, which exploits TLS servers implementing different protocols but using compatible certificates. By using man-in the-middle attack techniques, a remote attacker with access to victim’s traffic at the TCP/IP layer could redirect traffic from one subdomain to another, resulting in a valid TLS session. The session breaks the authentication of TLS and the packages become vulnerable to cross-protocol attacks.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/207761 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3.x Fix Pack 2 by following the instructions at <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=upgrade-upgrading-fix-pack-2.&gt;

Workarounds and Mitigations

None