Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
June 8, 2021
Rewterz
Rewterz Threat Alert – Nanocore Rat – Active IOCs
June 8, 2021

Rewterz Threat Advisory – Multiple Vulnerabilities in IBM API Connect

Severity

Medium

Analysis Summary

CVE-2020-14845, CVE-2020-14828, CVE-2020-14848, CVE-2020-14866, CVE-2020-14844, CVE-2020-14829, CVE-2020-14839, CVE-2020-14861, CVE-2020-14830, CVE-2020-14836, CVE-2020-14827, CVE-2020-14821, CVE-2020-14852, CVE-2020-14846, CVE-2020-14853, CVE-2020-14837, CVE-2020-14812, CVE-2020-14838, CVE-2020-14878, CVE-2020-14860, CVE-2020-14814

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. The easily exploitable vulnerability allows a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.

Impact

  • Unauthorized Access

Affected Vendors

IBM

Affected Products

  • IBM API Connect 2018.4.1
  • IBM API Connect 2018.4.1.16
  • IBM API Connect V5.0.0.0.0
  • IBM API Connect 5.0.8.10

Remediation

Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.

https://www.ibm.com/support/pages/node/6459931