Lucene search

K
ibmIBME597B7145EBAEECEE4609363C4654B59B52B2DFC047EA6F45AF6C7E8449281B5
HistoryApr 29, 2021 - 11:07 a.m.

Security Bulletin: IBM App Connect Enterprise Certified Container Designer Authoring components may be vulnerable to a denial of service attack (CVE-2020-28477)

2021-04-2911:07:30
www.ibm.com
14

0.002 Low

EPSS

Percentile

54.3%

Summary

A Designer Authoring component in App Connect Enterprise Certified Container may be vulnerable to a denial of service vulnerability due to a prototype polution vulnerability in one of the UI’s dependencies

Vulnerability Details

CVEID:CVE-2020-28477
**DESCRIPTION:**Node.js immer module is vulnerable to a denial of service, caused by a prototype pollution flaw. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195249 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Enterprise Certified Container 1.0 with Operator
App Connect Enterprise Certified Container 1.1 with Operator
App Connect Enterprise Certified Container 1.2 with Operator

Remediation/Fixes

App Connect Enterprise Certified Container 1.0 and 1.2 CD

Upgrade to App Connect Enterprise Certified Container to Operator version 1.3.0 (available in CASE 1.3.0) or higher, and ensure that all components are at 11.0.0.11-r2 or higher.

App Connect Enterprise Certified Container 1.1 LTS

Upgrade to App Connect Enterprise Certified Container Operator version 1.1.1 EUS (available in CASE 1.1.1) or higher, and ensure that all components are at 11.0.0.12-r1-eus or higher.

Workarounds and Mitigations

None

0.002 Low

EPSS

Percentile

54.3%

Related for E597B7145EBAEECEE4609363C4654B59B52B2DFC047EA6F45AF6C7E8449281B5