Lucene search

K
ibmIBMFFCEE877FE5D1EE7FD91076F0C8CB3DBF3EC47B4DCDE45D0BB88F932D6964DA3
HistoryApr 29, 2019 - 10:25 p.m.

Security Bulletin: API Connect V2018 is impacted by a vulnerability in Golang (CVE-2019-9741)

2019-04-2922:25:02
www.ibm.com
9

0.005 Low

EPSS

Percentile

76.0%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-9741
**DESCRIPTION:*Golang GO is vulnerable to HTTP header injection, caused by improper validation of input in the http.NewRequest. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
CVSS Base Score: 6.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/158137&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected IBM API Management Affected Versions
IBM API Connect 2018.1-2018.4.1.4

Remediation/Fixes

Affected releases Fixed in VRMF APAR Remediation / First Fix
IBM API Connect V2018.1-2018.4.1.4 2018.4.1.5 fixpack

LI80814

|

Addressed in IBM API Connect v2018.4.1.5 fixpack.

All components are impacted.

Follow this link and find the appropriate form factor for your installation: “management” , “portal”, “analytics” or apicup* or ICP for 2018.4.1.5.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=2018.4.1.4&platform=All&function=all&source=fc

Workarounds and Mitigations

None

0.005 Low

EPSS

Percentile

76.0%