Lucene search

K
ibmIBM1A4FA3B5469D18137712BF7AC1D07484A80FF90FF9C73C0DAEB585280189A01B
HistorySep 09, 2020 - 3:43 p.m.

Security Bulletin: vulnerabilities in Nimbus JOSE+JWT affect IBM Watson Machine Learning Accelerator 1.2.1

2020-09-0915:43:31
www.ibm.com
14

0.012 Low

EPSS

Percentile

85.4%

Summary

Vulnerabilities existing in the Nimbus JOSE+JWT version used by IBM Watson Machine Learning Accelerator 1.2.1. An interim fix that provides instructions on upgrading the Nimbus JOSE+JWT package to version 7.9 which resolves these vulnerabilities, are available on IBM Fix Central.

Vulnerability Details

CVEID:CVE-2019-17195
**DESCRIPTION:**Connect2id Nimbus JOSE+JWT is vulnerable to a denial of service, caused by the throwing of various uncaught exceptions while parsing a JWT. An attacker could exploit this vulnerability to crash the application or obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169514 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Machine Learning Accelerator 1.2.1

Remediation/Fixes

IBM Watson Machine Learning Accelerator 1.2.1 dli-1.2.3-build539837-wmla

Workarounds and Mitigations

None

0.012 Low

EPSS

Percentile

85.4%

Related for 1A4FA3B5469D18137712BF7AC1D07484A80FF90FF9C73C0DAEB585280189A01B