Use of insufficiently random values in crypto-js - CVE-2020-36732
Published: December 8, 2023
Vulnerability identifier: #VU83992
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-36732
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application generates random numbers by concatenating the string "0." with an
integer, which makes the output more predictable than necessary. A remote attacker can gain access to sensitive information.
Affected software
crypto-js
Enterprise Application Service for Java
Enterprise Application Runtimes
Operations Analytics - Log Analysis
PowerVM NovaLink
Financial Transaction Manager for RedHat OpenShift
WebSphere Hybrid Edition
Cloud Pak for Applications
Maximo Application Suite - Predict Component
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Verify Identity Access Digital Credentials
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Watson AIOps
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
IBM supplied MQ Advanced container images
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Robotic Process Automation
IBM Cloud Pak for Business Automation
IBM MQ Operator
IBM Sterling File Gateway
IBM Security Verify Access
IBM API Connect
IBM WebSphere Application Server Liberty
IBM CICS TX Advanced
IBM CICS TX Standard
Enterprise Application Service for Java
Enterprise Application Runtimes
Operations Analytics - Log Analysis
PowerVM NovaLink
Financial Transaction Manager for RedHat OpenShift
WebSphere Hybrid Edition
Cloud Pak for Applications
Maximo Application Suite - Predict Component
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Verify Identity Access Digital Credentials
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Watson AIOps
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
IBM supplied MQ Advanced container images
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM Robotic Process Automation
IBM Cloud Pak for Business Automation
IBM MQ Operator
IBM Sterling File Gateway
IBM Security Verify Access
IBM API Connect
IBM WebSphere Application Server Liberty
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2020-36732
Install updates from vendor's website.
crypto-js - update to 3.2.1
PowerVM NovaLink - addressed in versions 2.1.1-260119, 2.2.1.1-260119, 2.3.2-260116
Financial Transaction Manager for RedHat OpenShift - update to 4.0.9.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.32, 8.7.26, 9.0.19, 9.1.6
Maximo Application Suite - Predict Component - addressed in versions 8.8.12, 8.9.14, 9.0.11, 9.1.4
IBM Maximo Application Suite - addressed in versions 8.10.31, 8.11.28, 9.0.17, 9.1.6
Maximo Application Suite - Monitor Component - addressed in versions 8.10.26, 8.11.24, 9.0.16, 9.1.6
IBM API Connect - update to 10.0.8.5
IBM WebSphere Application Server Liberty - update to 25.0.0.10
IBM Robotic Process Automation - addressed in versions 23.0.20.5, 30.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.5, 30.0.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM MQ Operator - addressed in versions 3.2.19, 3.7.2, 9.4.4.0-r3
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
IBM supplied MQ Advanced container images - update to 9.4.4.0-r3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix44, 11.1.0.0 ifix36
IBM CICS TX Standard - update to 11.1.0.0 ifix37
PowerVM NovaLink - addressed in versions 2.1.1-260119, 2.2.1.1-260119, 2.3.2-260116
Financial Transaction Manager for RedHat OpenShift - update to 4.0.9.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.1.2.8, 6.2.0.5.2, 6.2.1.1.2, 6.2.2.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.32, 8.7.26, 9.0.19, 9.1.6
Maximo Application Suite - Predict Component - addressed in versions 8.8.12, 8.9.14, 9.0.11, 9.1.4
IBM Maximo Application Suite - addressed in versions 8.10.31, 8.11.28, 9.0.17, 9.1.6
Maximo Application Suite - Monitor Component - addressed in versions 8.10.26, 8.11.24, 9.0.16, 9.1.6
IBM API Connect - update to 10.0.8.5
IBM WebSphere Application Server Liberty - update to 25.0.0.10
IBM Robotic Process Automation - addressed in versions 23.0.20.5, 30.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.5, 30.0.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
IBM MQ Operator - addressed in versions 3.2.19, 3.7.2, 9.4.4.0-r3
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
IBM supplied MQ Advanced container images - update to 9.4.4.0-r3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix44, 11.1.0.0 ifix36
IBM CICS TX Standard - update to 11.1.0.0 ifix37
External References
- https://github.com/brix/crypto-js/issues/254
- https://security.snyk.io/vuln/SNYK-JS-CRYPTOJS-548472
- https://github.com/brix/crypto-js/issues/256
- https://github.com/brix/crypto-js/compare/3.2.0...3.2.1
- https://github.com/brix/crypto-js/pull/257/commits/e4ac157d8b75b962d6538fc0b996e5d4d5a9466b
- https://security.netapp.com/advisory/ntap-20230706-0003/
Related Security Bulletins
- Use of insufficiently random values in crypto-js
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- IBM WebSphere Application Server Liberty update for crypto-js package
- Use of insufficiently random values in IBM Cloud Pak for Applications
- Use of insufficiently random values in IBM Enterprise Application Runtimes
- Use of insufficiently random values in IBM WebSphere Hybrid Edition
- IBM Enterprise Application Service for Java update for crypto-js package
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- IBM OpenPages update for crypto-js package
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- IBM Maximo Application Suite - Monitor Component update for crypto-js package
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Use of insufficiently random values in IBM Maximo Application Suite - Predict Component
- IBM Operations Analytics - Log Analysis update for crypto.js
- IBM SPSS Analytic Server update for crypto-js package
- IBM Robotic Process Automation for Cloud Pak update for crypto-js package
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- IBM Maximo Application Suite - Manage Component update for crypto-js package
- IBM PowerVM Novalink update for crypto-js package
- IBM Sterling B2B Integrator and IBM Sterling File Gateway update for crypto-js package
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift