Wednesday, October 19, 2016

IBM Security Bulletin: Multiple vulnerabilities may affect IBM® SDK for Node.js™ in IBM Bluemix

OpenSSL vulnerabilities were disclosed on September 22 and 26, 2016 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs, plus three additional vulnerabilities unrelated to the OpenSSL release.

CVE(s): CVE-2016-6304, CVE-2016-6303, CVE-2016-2178, CVE-2016-6306, CVE-2016-2183, CVE-2016-7099, CVE-2016-5325

Affected product(s) and affected version(s):

These vulnerabilities affect IBM SDK for Node.js v1.1.1.3 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v1.2.0.14 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v4.5.0.0 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v6.6.0.0 and earlier releases.
The corresponding open-source versions are v0.10.46, v0.12.15 and v4.5.0, v6.6.0 respectively.

To check which version of the Node.js runtime runtime your Bluemix application is using, navigate to the “Files” menu item for your application through the Bluemix UI. In the “logs” directory, check the “staging_task.log”.

You can also find this file through the command-line Cloud Foundry client by running the following command:

cf files <appname> logs/staging_task.log

Look for the following lines:

—–> IBM SDK for Node.js Buildpack _______

If the Node.js engine version is not v0.10.47, v0.12.16, v4.6.0 or v6.7.0 your application may be vulnerable.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dnqGdE
X-Force Database: http://ift.tt/2dmY7tO
X-Force Database: http://ift.tt/2dmXjFz
X-Force Database: http://ift.tt/2asKHex
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2dckDn3
X-Force Database: http://ift.tt/2e5C4fq



from IBM Product Security Incident Response Team http://ift.tt/2dnoDWQ

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.