Lucene search

K
ibmIBM12DB796E1E5044849321DB8E749C954879CD7C3C7F511FA5273FD0958AE8BB96
HistoryJul 12, 2018 - 5:13 p.m.

Security Bulletin: IBM Security Guardium is affected by a OpenSource LibXML2 vulnerability

2018-07-1217:13:38
www.ibm.com
17

0.022 Low

EPSS

Percentile

89.4%

Summary

IBM Security Guardium has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2015-8806
DESCRIPTION: Libxml2 is vulnerable to a denial of service, caused by a heap-buffer overread in dict.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/110613&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product and Versions: IBM Security Guardium 10.1.3

Remediation/Fixes

Product VRMF Remediation / First Fix
IBM Security Guardium 10.1.3 http://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Securโ€ฆ

| |
โ€”|โ€”|โ€”
| |

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security guardiumeq10.1.3

0.022 Low

EPSS

Percentile

89.4%