Lucene search

K
ibmIBM34DA256B804615DAC44A47CD0E8F6E8731B8776022C84C698664BF5CA2C917ED
HistoryJun 17, 2018 - 3:49 p.m.

Security Bulletin: IBM Prospect is affected by Expat XML Parser vulnerability (CVE-2013-0340)

2018-06-1715:49:59
www.ibm.com
17

0.005 Low

EPSS

Percentile

77.0%

Summary

Prospect Core 8.0.7 Server is impacted by a denial of service vulnerability in Expat caused by the improper handling of internal entity expansion.

Vulnerability Details

CVEID**:**_CVE-_2013-0340
DESCRIPTION:
Expat is vulnerable to a denial of service, caused by the improper handling of internal entity expansion. By persuading a victim to open a specially crafted XML document, an attacker could exploit this vulnerability to consume all available resources.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/132738 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

Affected Products and Versions

IBM Prospect Core Server:

  • Version 8.0.7.13

Remediation/Fixes

A hotfix is available to update the Expat libraries to version 2.2.5. The hotfix also provides updated loader binaries as they are built using the static expat library.
Download the hotfix from <https://testcase.boulder.ibm.com/fromibm/8.0.7.13_HF05&gt;

Workarounds and Mitigations

None

CPENameOperatorVersion
prospecteq8.0.7

0.005 Low

EPSS

Percentile

77.0%