Lucene search

K
ibmIBM0B326B0926CF034A53EF8F84B4BF278BDF289D2CCB17BBC47BA764E652B86C85
HistoryAug 30, 2019 - 7:48 a.m.

Security Bulletin: Open Source Apache PDFBox Vulnerabilities in IBM Content Classification

2019-08-3007:48:35
www.ibm.com
19

0.001 Low

EPSS

Percentile

39.2%

Summary

Apache PDFBox could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.

Vulnerability Details

CVEID: CVE-2016-2175 DESCRIPTION: Apache PDFBox could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/113548 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Content Classification Versions 8.8

Remediation/Fixes

Product

| VRM|Remediation
—|—|—
IBM Content Classification| 8.8| Use IBM Content Classification 8.8 Interim Fix 8

Workarounds and Mitigations

None. Install the interim fix.

CPENameOperatorVersion
ibm content classificationeq8.8

0.001 Low

EPSS

Percentile

39.2%

Related for 0B326B0926CF034A53EF8F84B4BF278BDF289D2CCB17BBC47BA764E652B86C85