Lucene search

K
ibmIBM1EA85841223292DAD593366BFFE5E12E427C356CFF7D131B64AA5F0D365760E6
HistoryApr 03, 2020 - 8:08 a.m.

Security Bulletin: A vulnerability in Ruby on Rails affects IBM License Metric Tool v9 (CVE-2019-16782).

2020-04-0308:08:13
www.ibm.com
13

EPSS

0.002

Percentile

65.0%

Summary

There is a vulnerability in Ruby On Rails that is used by IBM License Metric Tool.

Vulnerability Details

CVEID:CVE-2019-16782
**DESCRIPTION:**Rack could allow a remote attacker to obtain sensitive information, caused by using the same session id for querying the backing session storage engine. By using timing attacks, an attacker could exploit this vulnerability to obtain session id information, and use this information to launch further attacks against the affected system.
CVSS Base score: 9.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/173273 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM License Metric Tool All

Remediation/Fixes

Upgrade to version 9.2.19 or later using the following procedure:

  • In BigFix console, expand IBM License Reporting (ILMT) node under Sites node in the tree panel.
  • Click Fixlets and Tasks node. Fixlets and Tasks panel will be displayed on the right.
  • In the Fixlets and Tasks panel locate _Upgrade to the latest version of IBM License Metric Tool _9.x fixlet and run it against the computer that hosts your server.

Workarounds and Mitigations

None