APAR status
Closed as program error.
Error description
CVE-2021-23358 underscore package
Local fix
Problem summary
<span style="font-size:12px"><span style="background-color:rgb(255, 255, 255);color:rgb(36, 41, 46);font-family:-apple-system,system-ui,segoe ui,helvetica,arial,sans-serif,apple color emoji,segoe ui emoji">The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.</span></span>
Problem conclusion
API Connect v5.0.8.11-iFix will contain underscore@1.12.1 and above, which will resolve this security concern.
Temporary fix
Comments
APAR Information
APAR number
LI82093
Reported component name
API CONNECT ENT
Reported component ID
5725Z2201
Reported release
508
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-04-09
Closed date
2021-04-13
Last modified date
2021-04-13
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
API CONNECT ENT
Fixed component ID
5725Z2201
Applicable component levels
R508 PSY
UP
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"508","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
29 September 2021