Lucene search

K
ibmIBM0DA6ACD096226DE5FDEDC80745B704E74BACA44A49B6BE52B56FA8A64B187869
HistoryJun 17, 2018 - 12:17 p.m.

Security Bulletin:Open Source Apache Poi Vulnerability in IBM eDiscovery Manager

2018-06-1712:17:11
www.ibm.com
11

0.006 Low

EPSS

Percentile

79.3%

Summary

Apache POI could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when XLSX2CSV example uses Java’s XML components to parse OpenXML files. An attacker could exploit this vulnerability using an XML document containing an external entity reference to read arbitrary files on the system.

Vulnerability Details

CVEID: CVE-2016-5000 DESCRIPTION: Apache POI could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when XLSX2CSV example uses Java’s XML components to parse OpenXML files. An attacker could exploit this vulnerability using an XML document containing an external entity reference to read arbitrary files on the system.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115530 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM eDiscovery Manager Version 2.2.2

Remediation/Fixes

Product

| VRM|Remediation
β€”|β€”|β€”
IBM eDiscovery Manager | 2.2.2| Use IBM eDiscovery Manager 2.2.2.2 Interim Fix IF0003 available at https://www-945.ibm.com/support/fixcentral/

Workarounds and Mitigations

NA

CPENameOperatorVersion
ediscovery managereq2.2.2

0.006 Low

EPSS

Percentile

79.3%

Related for 0DA6ACD096226DE5FDEDC80745B704E74BACA44A49B6BE52B56FA8A64B187869