Interim fixes are needed to upgrade the Spring Security OAuth package in IBM Spectrum Symphony 7.2.0.2 and 7.2.1 to resolve the remote code execution vulnerability (CVE-2018-1260).
CVEID: CVE-2018-1260 DESCRIPTION: Pivotal Spring Security OAuth could allow a remote attacker to execute arbitrary code on the system. By sending a specially crafted authorization request to the authorization endpoint, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base Score: 9.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/143171> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
IBM Spectrum Symphony 7.2.0.2 and 7.2.1
The fixes can be downloaded from IBM Fix Central:
sym-7.2.0.2-build496164:
sym-7.2.1-build496413:
None.
CPE | Name | Operator | Version |
---|---|---|---|
ibm spectrum symphony | eq | 7.2.0.2 | |
ibm spectrum symphony | eq | 7.2.1 |