QID 376115

Date Published: 2021-12-20

QID 376115: IBM Integration Bus Node.js Denial of Service (DoS) Vulnerability (6416609)

IBM Integration Bus enables information packaged as messages to flow between different business applications, ranging from large traditional systems through to unmanned devices such as sensors on pipelines.

CVE-2020-7760: Vulnerabilities in Node.js affect IBM Integration Bus

Affected Products and Versions:
IBM Integration Bus V10.0.0 - V10.0.0.23
codemirror before 5.58.2.

QID Detection Logic (Authenticated):
The QID checks if a vulnerable version of IBM Integration Bus and codemirror versions. NOTE: As per the advisory it is vulnerable for (Linux x86-64 and Windows x86-64 only).

A remote attacker could exploit this vulnerability to cause a denial of service condition.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Users are advised to follow the patching procedure provided by IBM. Further information can be obtained from IBM Security Bulletin 6416609
    Vendor References

    CVEs related to QID 376115

    Software Advisories
    Advisory ID Software Component Link
    6416609 URL Logo www.ibm.com/support/pages/node/6416609