DX UIM impact of CWE-190 (Integer Overflow or Wraparound)
search cancel

DX UIM impact of CWE-190 (Integer Overflow or Wraparound)

book

Article ID: 435136

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

A security scan has identified a CWE-190 (Integer Overflow or Wraparound) vulnerability risk within the DX Unified Infrastructure Management (UIM) Operator Console.

Environment

DX UIM Operator Console 23.4.7 (CU7) and prior

Cause

While the application logic correctly prevents an actual integer overflow from affecting system stability, the error handling mechanism is considered "too informative." It reveals technical details about the underlying technology stack and input constraints.

Resolution

This issue is identified as a product defect (DE666245). Engineering is updating the error handling logic to ensure that malformed inputs return a generic 400 Bad Request or a sanitized error message that does not disclose system internals.

Remediation Plan

Fix Version: This fix is scheduled for inclusion in DX UIM 23.4 Cumulative Update 8 (CU8). 

Additional Information

The tentative release date for CU8 (subject to change) is July 2026.