Risk | High |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2023-26136 CVE-2022-25883 |
CWE-ID | CWE-1321 CWE-185 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
IBM App Connect Enterprise Universal components / Libraries / Software for developers |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU80323
Risk: High
CVSSv3.1:
CVE-ID: CVE-2023-26136
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Install update from vendor's website.
Vulnerable software versionsIBM App Connect Enterprise: before 11.0.0.22
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7031733
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU78932
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-25883
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application via the new Range function and perform regular expression denial of service (ReDos) attack.
Install update from vendor's website.
Vulnerable software versionsIBM App Connect Enterprise: before 11.0.0.22
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/7031733
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?