About API-GW vulnerability

book

Article ID: 110134

calendar_today

Updated On:

Products

CA API Gateway (Layer 7) SA94 to API SECURITY STARTER PACK-7 CA Rapid App Security MOBILE API GATEWAY CA Mobile - API Gateway CA API Gateway

Issue/Introduction



Does API Gateway take the influence of the security vulnerability? 
If so, is the fix included in the product? 
・CVE-2018-1336 
・CVE-2018-2952 

Environment

API Gateway 8.3

Resolution

・CVE-2018-1336 :
* Gateway 8.3 product is not affected as it uses tomcat 6.


・CVE-2018-2952 :

* The affected Java concurrency subcomponent is a core component so Gateway 8.3 is probably affected to some extend but I can't say to what extent
* It is a low severity CVE, with difficult to exploit rating.
* Regardless whether the Gateway product is affected or not, the library fix (updated JDK version) will be delivered by the next CR (cumulative release) patch for Gateway 8.3 version but there is no known schedule for this yet
* Customer is recommended to migrate to Gateway 9.x to receive more frequent CR update that includes JDK updates.