HIGH
ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix
Published May 29, 2018
8.1
HIGHCVSS 3.0
EPSS 1.52%
Description
ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
Affected products
-
- Version <1.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HackerOne | IBM DB Node Module | n/a |
|
No data.
No Red Hat product state for this CVE.
ibm_db
npm
Introduced 0 Fixed 1.0.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ibm_db | 0 | 1.0.2 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0273 Advisory
- https://github.com/advisories/GHSA-c4qp-h3m6-785f Advisory
- https://github.com/ibmdb/node-ibm_db/commit/d7e2d4b4cbeb6f067df8bba7d0b2ac5d40fcfc19#diff-315091eb1586966006e05ebc21cd2a94 x_refsource_MISCPatchThird Party Advisory
- https://nodesecurity.io/advisories/163 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-10577
- https://www.npmjs.com/advisories/163
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0273 | Advisory | |
| https://github.com/advisories/GHSA-c4qp-h3m6-785f | Advisory | |
| https://github.com/ibmdb/node-ibm_db/commit/d7e2d4b4cbeb6f067df8bba7d0b2ac5d40fcfc19#diff-315091eb1586966006e05ebc21cd2a94 | x_refsource_MISCPatchThird Party Advisory | |
| https://nodesecurity.io/advisories/163 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-10577 | ||
| https://www.npmjs.com/advisories/163 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published May 29, 2018
Updated Sep 16, 2024
Reserved Oct 29, 2017
Link CVE-2016-10577
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0273 GHSA-C4QP-H3M6-785F Assigner hackerone
Published May 29, 2018
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2019-0273