Lucene search

K
ibmIBME8D5EF2C038DDFB9F908B86D5CCE58104B723647D2013CAE9B381D3EEAEA5C07
HistoryApr 11, 2022 - 3:16 p.m.

Security Bulletin: IBM App Connect Enterprise Certified Container IntegrationServers that use the Box connector may be vulnerable to arbitrary code execution due to CVE-2021-23555

2022-04-1115:16:41
www.ibm.com
22
ibm
app connect enterprise
certified container
integrationservers
box connector
vulnerability
arbitrary code execution
cve-2021-23555
node.js
vm2 module
patch
upgrade
fix

EPSS

0.002

Percentile

61.9%

Summary

Node.js module vm2 is used by IBM App Connect Enterprise Certified Container by the Box connector in a Designer flow. IBM App Connect Enterprise Certified Container IntegrationServers that use the Box connector may be vulnerable to CVE-2021-23555. This bulletin provides patch information to address the reported vulnerability CVE-2021-23555 in IntegrationServers.

Vulnerability Details

CVEID:CVE-2021-23555
**DESCRIPTION:**Node.js vm2 module could allow a remote attacker to execute arbitrary code on the system, caused by a sandbox bypass flaw during generation of a stacktraces. By sending a specially-crafted request via direct access to host error objects generated by node internals, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/219544 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Enterprise Certified Container 2.1 with Operator
App Connect Enterprise Certified Container 3.0 with Operator
App Connect Enterprise Certified Container 3.1 with Operator

Remediation/Fixes

App Connect Enterprise Certified Container 2.1, 3.0 and 3.1 (Continuous Delivery)

Upgrade to App Connect Enterprise Certified Container Operator version 4.0.0 or higher, and ensure that all DesignerAuthoring and IntegrationServer components are at 12.0.3.0-r2 or higher. Documentation on the upgrade process is available at <https://www.ibm.com/docs/en/app-connect/containers_cd?topic=releases-upgrading-operator&gt;

NoteApp Connect Enterprise Certified Container 1.1 EUS (Extended Update Support) is not affected by CVE-2021-23555

Workarounds and Mitigations

None

EPSS

0.002

Percentile

61.9%

Related for E8D5EF2C038DDFB9F908B86D5CCE58104B723647D2013CAE9B381D3EEAEA5C07