Input validation error in highcharts - CVE-2018-20801
Published: March 14, 2019 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS.
Affected software
API Manager
API Gateway
Qradar Advisor
How to mitigate CVE-2018-20801
API Manager - update to May 2022
API Gateway - update to May 2022
Qradar Advisor - update to 2.6.5