Lucene search

K
ibmIBM26B09B29AC9B0B47DC90FF4B39EBA83C52BA19DABE0A2F297ACCADB7482288F6
HistoryJun 17, 2018 - 3:48 p.m.

Security Bulletin: IBM Tivoli Netcool Impact affected by OpenSource Apache ActiveMQ Vulnerability (CVE-2015-5254)

2018-06-1715:48:25
www.ibm.com
13

0.039 Low

EPSS

Percentile

92.0%

Summary

IBM Tivoli Netcool Impact has addressed the OpenSource Apache ActiveMQ Vulnerability.

Vulnerability Details

CVEID:CVE-2015-5254**
DESCRIPTION: *Apache ActiveMQ could allow a remote attacker to execute arbitrary code on the system, caused by the failure to restrict the classes that can be serialized in the broker. An attacker could exploit this vulnerability using a specially crafted serialized Java Message Service (JMS) ObjectMessage object to execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109632 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

IBM Tivoli Netcool Impact 7.1.0

Remediation/Fixes

IBM Tivoli Netcool Impact

| 7.1.0.12| None| IBM Tivoli Netcool Impact 7.1.0 FP12
—|—|—|—

Please also note the****end of support announcementfrom 12 September 2017 for selected Netcool product versions. You can find detailed information on whether the product version you have installed in your environment is affected by this end of service announcement by following theNetcool End of Support Knowledge Collection**.**If your product version is affected, IBM recommend to upgrade your product version to the latest supported version of your product. Please contact your IBM account manager for any question you might have or for any assistance you may require for upgrading an end of service announced offering.

CPENameOperatorVersion
tivoli netcool/impacteq7.1.0

0.039 Low

EPSS

Percentile

92.0%