Lucene search

K
ibmIBM046428A87C546167D8D7B6AEB02CA35DAAFD221003DB532DD3576E9C3D917636
HistoryJul 10, 2019 - 3:05 p.m.

Security Bulletin: IBM QRadar Incident Forensics is vulnerable to publicly disclosed vulnerabilities from Apache Tika (CVE-2018-11761, CVE-2018-11762, CVE-2018-8017, ย CVE-2018-11796)

2019-07-1015:05:01
www.ibm.com
16

EPSS

0.012

Percentile

85.6%

Summary

Open source Apache Tika as used in IBM QRadar Incident Forensics is affected by multiple vulnerabilities

Vulnerability Details

CVEID: CVE-2018-11761
**Description:**Apache Tika is vulnerable to a denial of service, caused by the failure to configure XML parsers to limit entity expansion. A remote attacker could exploit this vulnerability to cause a denial of service.
**CVSS Base Score:**5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/150101&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVEID: CVE-2018-11762
**Description:**Apache Tika could allow a remote attacker to overwrite arbitrary files on the system, caused by the failure to specify an extract directory on the commandline and the input file has an embedded file. An attacker could exploit this vulnerability to overwrite a file.
**CVSS Base Score:**3.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/150100&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CVEID: CVE-2018-8017
**Description:**Apache Tika is vulnerable to a denial of service, caused by an error in the IptcAnpaParser. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
**CVSS Base Score:**4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/150099&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVEID:CVE-2018-11796

**Description:**Apache Tika is vulnerable to a denial of service, caused by a flaw during XML parsing. A remote attacker could exploit this vulnerability to cause the application to crash.

**CVSS Base Score:**5.3

CVSS Temporal Score: See<https://exchange.xforce.ibmcloud.com/vulnerabilities/151083&gt; for the current score

**CVSS Environmental Score:***Undefined

**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products and Versions

ยท IBM QRadar 7.3 to 7.3.2 GA

ยท IBM QRadar 7.2 to 7.2.8 Patch 15

Remediation/Fixes

IBM QRadar/QRM/QVM/QRIF/QNI 7.3.2 Patch 1

IBM QRadar/QRM/QVM/QRIF/QNI 7.3.1 Patch 8

IBM QRadar/QRM/QVM/QRIF/QNI 7.2.8 Patch 16

Workarounds and Mitigations

None

EPSS

0.012

Percentile

85.6%

Related for 046428A87C546167D8D7B6AEB02CA35DAAFD221003DB532DD3576E9C3D917636