About API-GW vulnerability

Document ID : KB000110134
Last Modified Date : 30/08/2018
Show Technical Document Details
Question:
Does API Gateway take the influence of the security vulnerability? 
If so, is the fix included in the product? 
・CVE-2018-1336 
・CVE-2018-2952 
Environment:
API Gateway 8.3
Answer:
・CVE-2018-1336 :
* Gateway 8.3 product is not affected as it uses tomcat 6.


・CVE-2018-2952 :

* The affected Java concurrency subcomponent is a core component so Gateway 8.3 is probably affected to some extend but I can't say to what extent
* It is a low severity CVE, with difficult to exploit rating.
* Regardless whether the Gateway product is affected or not, the library fix (updated JDK version) will be delivered by the next CR (cumulative release) patch for Gateway 8.3 version but there is no known schedule for this yet
* Customer is recommended to migrate to Gateway 9.x to receive more frequent CR update that includes JDK updates.