High Severity

IBM Security Bulletin: IBM Cloud Functions is affected by two function runtimevulnerabilities

Share this post:

IBM Cloud Functions has addressed the following vulnerabilities. Users of the IBM Cloud Functions service that are using docker actions (https://console.bluemix.net/docs/openwhisk/openwhisk_actions.html#creating-docker-actions) are affected but only if the user’s function has a general security vulnerability. In this context general vulnerability means for example parameter hijacking, remote code execution or wrong usage of “eval()” (generally addressed via secure engineering best practices). With this vulnerability being present, an attacker can exploit an Apache OpenWhisk specific vulnerability to overwrite the user functions code that is then executed in subsequent executions of the same user’s function. The CVE listed below only refer to the ability to overwrite the action code. The general vulnerability which is a pre-condition for these CVEs is out of scope of this document as it is subject to general secure engineering best practices. Exploitation of the issue is only possible if the user included function code is vulnerable. The vulnerability only affects users with action code that is vulnerable in the first place. Other users who followed general secure engineering best practices are not affected.

CVE(s): CVE-2018-11756, CVE-2018-11757

Affected product(s) and affected version(s):

IBM Cloud Functions service by using custom docker images.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10718977
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147372
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/147371

More stories

IBM Security Bulletin: Node.js vulnerabilities affect IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518)

Sep 21, 2019 9:02 am EDT | High Severity

Node.js denial of service vulnerabilities affect IBM Spectrum Control (formerly Tivoli Storage Productivity Center). CVE(s): CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, CVE-2019-9515, CVE-2019-9516, CVE-2019-9517, CVE-2019-9518 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Spectrum Control 5.3.0 – 5.3.3 Note that the 5.2 release is not affected. Refer to the following reference URLs for remediation and ...read more


IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-2684, CVE-2019-4473, CVE-2019-11771)

Sep 21, 2019 9:01 am EDT | High Severity

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition that is shipped and used by IBM Spectrum Control (formerly Tivoli Storage Productivity Center). These issues were disclosed as part of the IBM Java SDK updates for April 2019 and July 2019. CVE(s): CVE-2019-2684, CVE-2019-4473, CVE-2019-11771 Affected product(s) and affected version(s): Affected Product Affected Versions ...read more


IBM Security Bulletin: Multiple vulnerabilities in Oracle Outside In Technology affect IBM Rational DOORS Next Generation

Sep 20, 2019 9:02 am EDT | High Severity

IBM Rational DOORS Next Generation® is affected by multiple vulnerabilities in the Oracle Outside In Technology® that is used as a component. CVE(s): CVE-2019-2756, CVE-2019-2855, CVE-2019-2852, CVE-2019-2764, CVE-2019-2792, CVE-2019-2759, CVE-2019-2835, CVE-2019-2854, CVE-2019-2853 Affected product(s) and affected version(s): Rational DOORS Next Generation 6.0.6.1 Previous versions are not affected. Refer to the following reference URLs for remediation ...read more