IBM Security Bulletin: Multiple vulnerabilities affect IBM® SDK for Node.js™ in IBM Cloud
Sep 12, 2018 9:00 am EDT
Categorized: High Severity
Share this post:
OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js for IBM Cloud. IBM SDK for Node.js for IBM Cloud has addressed the applicable CVEs. Security vulnerabilities have been reported in Node.js that affect IBM® SDK for Node.js™ in IBM Cloud.
CVE(s): CVE-2018-0732, CVE-2018-12115, CVE-2018-7166, CVE-2018-0737, CVE-2018-7167, CVE-2018-7164, CVE-2018-7162, CVE-2018-1000168, CVE-2018-7161
Affected product(s) and affected version(s):
These vulnerabilities affect IBM SDK for Node.js v6.14.3 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v8.11.3 and earlier releases.
You can also find this file through the command-line Cloud Foundry client by running the following command:
cf ssh
Look for the following lines:
{“detected_buildpack”:”SDK for Node.js(TM) (ibm-node.js-xxx, buildpack-v3.xxx)”,”start_command”:”./vendor/initial_startup.rb”}
If the Node.js engine version is not at least v6.14.4 or v8.11.4 your application may be vulnerable.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22012749
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144658
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148426
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148425
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141679
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144740
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144739
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144738
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141584
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144736
from IBM Product Security Incident Response Team https://ift.tt/2x6cyNQ