Lucene search

K
ibmIBM265337C80A8A17DE11A442CE56ACC754F9D5D1EF8A38FB8BC779DE0A3CBE19C3
HistoryJun 17, 2018 - 12:18 p.m.

Security Bulletin: Vulnerability in IBM SDK, Java Technology Edition Quarterly CPU - Apr 2017 - Includes Oracle Apr 2017 CPU affect IBM Content Collector for SAP Applications

2018-06-1712:18:34
www.ibm.com
7

0.002 Low

EPSS

Percentile

61.1%

Summary

There is vulnerability in IBM® SDK Java™ Technology Edition, Java™ Version 6 and Java™ Version 7 that is used by Content Collector for IBM Content Collector for SAP Applications. These issues were disclosed as part of the IBM Java SDK updates in Apr 2017.

Vulnerability Details

CVEID: CVE-2017-1289**
DESCRIPTION:** IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources.
CVSS Base Score: 8.2
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/125150&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)

Affected Products and Versions

IBM Content Collector for SAP Applications v3.0

IBM Content Collector for SAP Applications v4.0

Remediation/Fixes

Product

| VRM|Remediation
—|—|—
IBM Content Collector for SAP Applications| 3.0| Use IBM Content Collector for SAP Applications Fix Pack 002
IBM Content Collector for SAP Applications| 4.0| Use IBM Content Collector for SAP Applications Fix Pack 001

Workarounds and Mitigations

None

0.002 Low

EPSS

Percentile

61.1%

Related for 265337C80A8A17DE11A442CE56ACC754F9D5D1EF8A38FB8BC779DE0A3CBE19C3