Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in node-xml2js - CVE-2023-0842
Published: May 1, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited. A remote unauthenticated attacker can edit or add new properties to an object to execute arbitrary code on the target system.
Affected software
IBM App Connect Enterprise
IBM Cloud Pak for Multicloud Management
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Integration Bus
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite
Voice Gateway
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Cloud Pak for Watson AIOps
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Security QRadar Analyst Workflow
IBM QRadar Use Case Manager
How to mitigate CVE-2023-0842
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
Voice Gateway - addressed in versions 1.0.8.4, 1.0.8.7, 1.0.8.9
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Security QRadar Analyst Workflow - update to 2.32.0
IBM QRadar Use Case Manager - update to 3.8.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
IBM Decision Optimization for Cloud Pak for Data - update to 4.7
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
IBM App Connect Enterprise - addressed in versions 11.0.0.21, 12.0.8.0
External References
Related Security Bulletins
- Prototype pollution in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Voice Gateway
- Improperly controlled modification of object prototype attributes in IBM App Connect Enterprise and IBM Integration Bus
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Improperly controlled modification of object prototype attributes in IBM Decision Optimization for Cloud Pak for Data
- Improperly controlled modification of object prototype attributes in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Knowledge Catalog for IBM Cloud Pak for Data
- IBM Maximo Application Suite update for xml2js
- Multiple vulnerabilities in IBM QRadar Use Case Manager
- Multiple vulnerabilities in IBM Analyst Workflow
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Improperly controlled modification of object prototype attributes ('Prototype Pollution') in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)