Lucene search

K
ibmIBM19C76C5B3FDC0D71CECCC0547185F376A4CB3B63C7810C50C2FC2E6DB2DAAB2F
HistoryOct 28, 2020 - 4:21 p.m.

Security Bulletin: Security Vulnerabilities affect IBM Cloud Pak for Data - Golang (CVE-2020-16845)

2020-10-2816:21:54
www.ibm.com
12

0.037 Low

EPSS

Percentile

91.9%

Summary

Security Vulnerabilities affect IBM Cloud Pak for Data - Golang (CVE-2020-16845)

Vulnerability Details

CVEID:CVE-2020-16845
**DESCRIPTION:**Go Language is vulnerable to a denial of service, caused by an infinite read loop in ReadUvarint and ReadVarint in encoding/binary. By sending a specially-crafted input, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/186375 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
CP4D 2.5.0
CP4D 3.0.1

Remediation/Fixes

Patch:
<https://www.ibm.com/support/pages/node/6327429&gt;

Users of IBM Cloud Pak for Data V2.5 are advised to:
Apply IBM Cloud Pak for Data V2.5 cpd-2.5.0.0-lite-patch-6

Users of IBM Cloud Pak for Data V3.0.1 are advised to:
Apply IBM Cloud Pak for Data V3.0.1 cpd-3.0.1-lite-patch-6

Workarounds and Mitigations

None