Lucene search

K
ibmIBM3B3E4934A1311D9F2F3AA35A307317A5EA2FD3724495C2445F3383B90C432628
HistorySep 25, 2023 - 9:06 a.m.

Security Bulletin: Multiple vulnerabilities in Apache Camel core affect IBM Application Performance Management products

2023-09-2509:06:33
www.ibm.com
18
apache camel
ibm application performance management
vulnerabilities
remote attacker
executing arbitrary code
sensitive information
xml entities
java object de-serialization
xml external entity
cve-2014-0002
cve-2017-12633
cve-2015-0264
cve-2015-5344
cve-2015-0263
cve-2013-4330

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.358 Low

EPSS

Percentile

97.2%

Summary

Apache Camel core is used by IBM Application Performance Management. The vulnerabilities in the product component have been addressed.

Vulnerability Details

CVEID:CVE-2014-0002
**DESCRIPTION:**Apache Camel could allow a remote attacker to obtain sensitive information, caused by an error in the XSLT component when parsing XML entities. By persuading a victim to open a specially-crafted XML document containing external entity references, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/91573 for the current score.
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVEID:CVE-2017-12633
**DESCRIPTION:**Apache Camel could allow a remote attacker to execute arbitrary code on the system, caused by Java object de-serialisation vulnerability in the camel-hessian component. By using deserialized untrusted data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 7.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/135094 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2015-0264
**DESCRIPTION:**Apache Camel could allow a remote attacker to obtain sensitive information, caused by an error related to the XPath handling of invalid XML Strings or invalid XML GenericFile objects. An attacker could exploit this vulnerability using an XML External Entity (XXE) declaration to read arbitrary files on the system.
CVSS Base score: 5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/101581 for the current score.
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID:CVE-2015-5344
**DESCRIPTION:**Apache Camel could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data by the camel-xstream component. An attacker could exploit this vulnerability using specially crafted data to execute arbitrary Java code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/110297 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2015-0263
**DESCRIPTION:**Apache Camel could allow a remote attacker to obtain sensitive information, caused by an error in the XML converter setup. An attacker could exploit this vulnerability using an SAXSource containing an XML External Entity (XXE) declaration to read arbitrary files on the system.
CVSS Base score: 5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/101580 for the current score.
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID:CVE-2013-4330
**DESCRIPTION:**Apache Camel could allow a remote attacker to execute arbitrary code on the system, caused by the improper handling of simple language expressions. An attacker could exploit this vulnerability to execute arbitrary code on the system with elevated privileges.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/87542 for the current score.
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud APM, Base Private 8.1.4
IBM Cloud APM, Advanced Private 8.1.4

Remediation/Fixes

IBM Cloud Application Performance Management, Base Private

IBM Cloud Application Performance Management, Advanced Private| 8.1.4|

The vulnerability can be remediated by applying the following 8.1.4.0-IBM-APM-SERVER-IF0014 or later server patch to the system where the Cloud APM server is installed: <https://www.ibm.com/support/pages/node/7028410&gt;

—|—|—

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapplication_performance_managementMatch8.1.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.358 Low

EPSS

Percentile

97.2%

Related for 3B3E4934A1311D9F2F3AA35A307317A5EA2FD3724495C2445F3383B90C432628