Lucene search

K
ibmIBM5576EEA2DF691EAC77F2C4BB7842AF04E1A593D5E464D25C0AB4BB3BFB8D8819
HistoryDec 01, 2021 - 2:55 p.m.

Security Bulletin: IBM Cloud Pak for Multicloud Management has applied security fixes for its use of Apache Commons

2021-12-0114:55:48
www.ibm.com
10
ibm cloud pak
multicloud management
apache commons
security fix

EPSS

0.006

Percentile

79.2%

Summary

IBM Cloud Pak for Multicloud Management has applied security fixes for its use of Apache Commons.

Vulnerability Details

CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Monitoring before 2.3 Fix Pack 2

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3 Fix Pack 2 by following the instructions at <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=installation-upgrade&gt;

Workarounds and Mitigations

None

EPSS

0.006

Percentile

79.2%

Related for 5576EEA2DF691EAC77F2C4BB7842AF04E1A593D5E464D25C0AB4BB3BFB8D8819