Prototype pollution in Hoek - CVE-2020-36604

 

Prototype pollution in Hoek - CVE-2020-36604

Published: June 20, 2023


Vulnerability identifier: #VU77566
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-36604
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.


Affected software

Hoek
IBM Cloud Pak for Watson AIOps
Storage Defender Copy Data Management
Business Automation Insights
IBM Cloud Pak for Business Automation
App Connect Enterprise Certified Container

How to mitigate CVE-2020-36604

Install updates from vendor's website.

Hoek - addressed in versions 8.5.1, 9.0.3
Storage Defender Copy Data Management - update to 2.3.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0

External References

Related Security Bulletins