Vulnerabilities existing in the Nimbus JOSE+JWT version used by IBM Watson Machine Learning Accelerator 1.2.1. An interim fix that provides instructions on upgrading the Nimbus JOSE+JWT package to version 7.9 which resolves these vulnerabilities, are available on IBM Fix Central.
CVEID:CVE-2019-17195
**DESCRIPTION:**Connect2id Nimbus JOSE+JWT is vulnerable to a denial of service, caused by the throwing of various uncaught exceptions while parsing a JWT. An attacker could exploit this vulnerability to crash the application or obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169514 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
Affected Product(s) | Version(s) |
---|---|
IBM Watson Machine Learning Accelerator | 1.2.1 |
IBM Watson Machine Learning Accelerator 1.2.1 | dli-1.2.3-build539837-wmla |
---|
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm watson machine learning accelerator | eq | 1.2.1 |