Lucene search

K
ibmIBM0D5D9C62E3772E12A0A361D23CC8D2FE21F9AD572A09912E906D408ED2270FAA
HistoryNov 08, 2021 - 4:32 a.m.

Security Bulletin: A vulnerability in Apache Commons Compress Library affects IBM LKS ART and Agent

2021-11-0804:32:13
www.ibm.com
11

0.012 Low

EPSS

Percentile

85.1%

Summary

A ZIP processing vulnerability has been found in Apache Commons Compress. It affects IBM License Key Server Administration & Reporting Tool and its Agent. A mitigation has been released.

Vulnerability Details

CVEID:CVE-2021-36090
**DESCRIPTION:**Apache Commons Compress is vulnerable to a denial of service, caused by an out-of-memory error when large amounts of memory are allocated. By reading a specially-crafted ZIP archive, a remote attacker could exploit this vulnerability to cause a denial of service condition against services that use Compress’ zip package.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/205310 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Common Licensing Agent 9.0
IBM Common Licensing ART 9.0

Remediation/Fixes

Upgrade to ART/Agent version 9.0 iFix 5. It can be downloaded from Fix Central.

Workarounds and Mitigations

None

CPENameOperatorVersion
rational license key servereq9.0

0.012 Low

EPSS

Percentile

85.1%