Security Bulletin: IBM DataPower Gateway is vulnerable to Denial of Service due to use of Node.js
Discription

Summary NodeJS is used by IBM DataPower Gateway as part of the API-GWY management interface (CVE-2024-22019) Vulnerability Details ** CVEID: CVE-2024-22019 DESCRIPTION: **Node.js is vulnerable to a denial of service, caused by an error when reading unprocessed HTTP request with unbounded chunk extension. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to exhaust all available resources. CVSS Base score: 7.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/282988 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM DataPower Gateway 10.5 CD| 10.5.1 – 10.5.3 IBM DataPower Gateway 10.0.1| 10.0.1.0 – 10.0.1.17 IBM DataPower Gateway 10.5.0| 10.5.0.0 – 10.5.0.9 Remediation/Fixes IBM strongly recommends addressing the vulnerability now by installing the following APARs Affected Product| Fixed in Version| APAR —|—|— IBM DataPower Gateway 10.5 CD| 10.5.4| IT45576 IBM DataPower Gateway 10.0.1| 10.0.1.18| IT45576 IBM DataPower Gateway 10.5.0| 10.5.0.10| IT45576 Workarounds and Mitigations…Read More

Back to Main

Subscribe for the latest news: