IBM Support

JR62923: SECURITY APAR - CVE-2020-13822, CVE-2020-8244, AND CVE-2020-15168 AFFECT IBM BUSINESS AUTOMATION APPLICATION

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The following security issues in IBM Business Automation
    Application occur because of CVE-2020-13822, CVE-2020-8244, and
    CVE-2020-15168.
    
    
    CVEID: CVE-2020-13822
    Description: The Elliptic package 6.5.2 for Node.js allows ECDSA
    signature malleability via variations in encoding, leading '\0'
    bytes, or integer overflows. This could conceivably have a
    security-relevant impact if an application relied on a single
    canonical signature.
    CVSS Base Score: 9.8
    CVSS Temporal Score:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/184099 for
    more information
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
    
    CVEID: CVE-2020-8244
    Description: Node.js bl module could allow a remote attacker to
    obtain sensitive information, caused by a buffer over-read flaw
    in the consume function. By sending a specially-crafted
    argument, an attacker could exploit this vulnerability to obtain
    sensitive information, or cause a denial of service condition.
    CVSS Base Score: 8.2
    CVSS Temporal Score:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/187518 for
    more information
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)
    
    CVEID: CVE-2020-15168
    Description: Node.js node-fetch module is vulnerable to a denial
    of service, caused by the failure to honor the size option after
    following a redirect. By using a specially-crafted file, a
    remote attacker could exploit this vulnerability to consume
    excessive resource on the system.
    CVSS Base Score: 7.5
    CVSS Temporal Score:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/188155 for
    more information
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
    
    PRODUCTS AFFECTED
    IBM Cloud Pak for Automation - Business Automation Application
    IBM Cloud Pak for Automation - Business Automation Studio
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available for the last fix pack of all affected
    supported releases as well as the last two releases of Single
    Stream Continuous Delivery (SSCD).
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR62923

  • Reported component name

    CLOUD PAK FOR A

  • Reported component ID

    5737I2300

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-10-27

  • Closed date

    2020-12-14

  • Last modified date

    2020-12-14

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CLOUD PAK FOR A

  • Fixed component ID

    5737I2300

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"K00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
11 March 2022