Lucene search

K
ibmIBM3E6B657C015C16954B98859793FD033350A73E948A9B34DC9CE852E2232B7B0D
HistoryOct 14, 2020 - 12:51 p.m.

Security Bulletin: Netcool Operations Insight component IBM Network Performance Insight 1.3.1 affected by CVE-2020-14062

2020-10-1412:51:16
www.ibm.com
14
netcool operations insight
ibm network performance insight
cve-2020-14062
fasterxml jackson-databind
remote attacker
arbitrary code
unsafe deserialization
xalan2
cvss base score 9.8
hotfix
download url

EPSS

0.053

Percentile

93.1%

Summary

Netcool Operations Insight component IBM Network Performance Insight 1.3.1 affected by CVE-2020-14062

Vulnerability Details

CVEID:CVE-2020-14062
**DESCRIPTION:**FasterXML jackson-databind could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/183425 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Network Performance Insight 1.3.1

Remediation/Fixes

NPI code updated to resolve CVE-2020-14062 in the hotfix mentioned as follows. this hotfix will be included in subsequent Interim Fix and Major release

IBM Network Performance Insight (1.3.1) - Hotfix

Download URL: <https://www.secure.ecurep.ibm.com/download/?id=G74EtIgSA5nOgY587MtOAjSnt1wk8bRD4nauc0mSakk&gt;

Workarounds and Mitigations

None

EPSS

0.053

Percentile

93.1%