CVE-2019-4222
published 2019-04-25CVE-2019-4222: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.17%
63.8th percentile
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18802 envoy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure
bugzilla·2019-11-18·CVSS 9.8
CVE-2019-18802 [CRITICAL] CVE-2019-18802 envoy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure
CVE-2019-18802 envoy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure
Malformed request header may cause route matchers or access controls to be bypassed, resulting in escalation of privileges or information disclosure.
Discussion:
External References:
https://groups.google.com/forum/#!topic/envoy-users/m7z5fGkCzPI
https://github.com/envoyproxy/envoy/security/advisories/GHSA-356m-vhw2-wcm4
---
This issue has been addressed in the following products:
Openshift Service Mesh 1.0
OpenShift Service Mesh 1.0
Via RHSA-2019:4222 https://access.redhat.com/errata/RHSA-2019:4222
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securi
Bugzilla
CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
bugzilla·2019-11-18·CVSS 7.5
CVE-2019-18838 [HIGH] CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
CVE-2019-18838 envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
Malformed HTTP request without the Host header may cause abnormal termination of the Envoy process
Discussion:
Note the alias for this issue is CVE-1019-18838 but should be CVE-2019-18838, I've updated the summary but there appears to be something else to be updated by the security team. Tim added the same comment on 25th November.
---
External References:
https://groups.google.com/forum/#!topic/envoy-users/m7z5fGkCzPI
https://github.com/envoyproxy/envoy/security/advisories/GHSA-f2rv-4w6x-rwhc
---
This issue has been addressed in the following products:
Openshift Service Mesh 1.0
OpenShift Service Mesh 1.0
Via RHSA-2019:4222 https://access.redhat.com/errata/RHS
http://www.securityfocus.com/bid/108110https://exchange.xforce.ibmcloud.com/vulnerabilities/159231https://www.ibm.com/support/docview.wss?uid=ibm10880595http://www.securityfocus.com/bid/108110https://exchange.xforce.ibmcloud.com/vulnerabilities/159231https://www.ibm.com/support/docview.wss?uid=ibm10880595
2019-04-25
Published