Lucene search

K
ibmIBMF6980355BB9F9DEBEB1CC5C0DF4DECE9500FC803408B070C54D52A218AAD5A14
HistoryJul 19, 2024 - 9:47 a.m.

Security Bulletin: IBM App Connect Enterprise Certified Container Operations Dashboard is vulnerable to denial of service [CVE-2024-36129]

2024-07-1909:47:29
www.ibm.com
5
ibm app connect enterprise
operations dashboard
denial of service
opentelemetry
patch
upgrade

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

AI Score

6.5

Confidence

High

Summary

OpenTelemetry is used by IBM App Connect Enterprise Certified Container for the Operations Dashboard. IBM App Connect Enterprise Certified Container Operations Dashboard is vulnerable to denial of service. This bulletin provides patch information to address the reported vulnerability in OpenTelemetry. [CVE-2024-36129]

Vulnerability Details

CVEID:CVE-2024-36129
**DESCRIPTION:**OpenTelemetry OpenTelemetry Collector is vulnerable to a denial of service, caused by an unsafe decompression vulnerability. By sending a zip bomb or decompression bomb using a specially crafted HTTP or gRPC request, a remote attacker could exploit this vulnerability to cause a resource consumption.
CVSS Base score: 8.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/294097 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Enterprise Certified Container 5.0-lts

Remediation/Fixes

IBM strongly suggests the following:

App Connect Enterprise Certified Container 5.0 LTS (Long Term Support)

If the operations dashboard is enabled, then upgrade to App Connect Enterprise Certified Container Operator version 5.0.19 or higher, and ensure that all components are at 12.0.12.3-r1-lts or higher. Documentation on the upgrade process is available at <https://www.ibm.com/docs/en/app-connect-contlts?topic=releases-upgrading-operator&gt;

App Connect Enterprise Certified Container continuous delivery versions and 12.0 LTS (Long Term Support) versions are not affected

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseMatch5.0
VendorProductVersionCPE
ibmapp_connect_enterprise5.0cpe:2.3:a:ibm:app_connect_enterprise:5.0:*:*:*:*:*:*:*

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

AI Score

6.5

Confidence

High

Related for F6980355BB9F9DEBEB1CC5C0DF4DECE9500FC803408B070C54D52A218AAD5A14