Improper input validation in etcd - CVE-2018-1099
Published: April 5, 2018 / Updated: April 10, 2018
Vulnerability identifier: #VU11633
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1099
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.
The weakness exists due to improper validation of DNS hostnames. A remote attacker can send specially crafted requests, bypass security restrictions and gain network access to internal systems.
The weakness exists due to improper validation of DNS hostnames. A remote attacker can send specially crafted requests, bypass security restrictions and gain network access to internal systems.
Affected software
etcd
IBM Cloud Pak for Security
QRadar Suite
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Cloud Pak for Security
QRadar Suite
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2018-1099
Update to version 3.3.2 or later.
QRadar Suite - update to 1.10.19.0
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
External References
Related Security Bulletins
- Multiple vulnerabilities in CoreOS etcd
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Storage Protect Server
- Fedora 30 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd