QID 378994
Date Published: 2023-12-27
QID 378994: IBM App Connect Enterprise Toolkit Denial of Service (DoS) Vulnerability (7056518)
IBM App Connect Enterprise Toolkit using Maven projects feature are vulnerable to a denial of service due to Okio GzipSource.
Affected Products and Versions:
IBM App Connect Enterprise 11.0.0.1 - 11.0.0.23
IBM App Connect Enterprise 12.0.1.0 - 12.0.10.0
Note: This QID does not checks for the install interfix fix and only checks for the vulnerable installed version. Hence kept as practice
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks if a vulnerable version of IBM Integration Bus and IBM App Connect Enterprise is installed on the system.
By sending a specially crafted gzip buffer, a remote attacker could exploit this vulnerability to cause a denial of service.
Solution
Users are advised to follow the patching procedure provided by IBM. Further information can be obtained from IBM Security Bulletin (7056518)
Vendor References
- 7056518 -
www.ibm.com/support/pages/node/7056518
CVEs related to QID 378994
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7056518 |
|