Lucene search

K
ibmIBM0014B28ACA7F9997C72146507BEEC1742A1789CC46F9FF03799C7B89A0B39408
HistoryFeb 10, 2022 - 4:05 p.m.

Security Bulletin: IBM Cloud Private is vulnerable to FasterXML jackson-databind vulnerabilities (CVE-2020-24750)

2022-02-1016:05:03
www.ibm.com
16
ibm cloud private
vulnerability
fasterxml jackson-databind
cve-2020-24750
remote code execution
deserialization
security updates
continuous delivery
fix pack
upgrade
ibm support

EPSS

0.007

Percentile

80.7%

Summary

IBM Cloud Private is vulnerable to FasterXML jackson-databind vulnerabilities

Vulnerability Details

CVEID:CVE-2020-24750
**DESCRIPTION:**FasterXML jackson-databind could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization between gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/188470 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Private 3.1.0
IBM Cloud Private 3.1.1
IBM Cloud Private 3.1.2
IBM Cloud Private 3.2.0
IBM Cloud Private 3.2.1 CD
IBM Cloud Private 3.2.2 CD

Remediation/Fixes

Product defect fixes and security updates are only available for the two most recent Continuous Delivery (CD) update packages

  • IBM Cloud Private 3.2.1
  • IBM Cloud Private 3.2.2

For IBM Cloud Private 3.2.1, apply fix pack:

For IBM Cloud Private 3.2.2, apply fix pack:

For IBM Cloud Private 3.1.0, 3.1.1, 3.1.2, 3.2.0:

  • Upgrade to the latest Continuous Delivery (CD) update package, IBM Cloud Private 3.2.2.
  • If required, individual product fixes can be made available between CD update packages for resolution of problems. Contact IBM support for assistance

Workarounds and Mitigations

None

EPSS

0.007

Percentile

80.7%