SB2023061639 - Uncaught exception inj IBM App Connect Enterprise Certified Container
Published: June 16, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Uncaught Exception (CVE-ID: CVE-2022-41940)
The vulnerability allows a remote user to perform denial of service attacks.
The vulnerability exists due to an uncaught exception. A remote user can send specially crafted HTTP request to trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.
Remediation
Install update from vendor's website.