Improper input validation in etcd - CVE-2018-1099

 

Improper input validation in etcd - CVE-2018-1099

Published: April 5, 2018 / Updated: April 10, 2018


Vulnerability identifier: #VU11633
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1099
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.

The weakness exists due to improper validation of DNS hostnames. A remote attacker can send specially crafted requests, bypass security restrictions and gain network access to internal systems.

Affected software

etcd
IBM Cloud Pak for Security
QRadar Suite
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2018-1099

Update to version 3.3.2 or later.

QRadar Suite - update to 1.10.19.0
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6

External References

Related Security Bulletins