Lucene search

K
ibmIBM57F776FF55271032943DDA94EDAE416CC0AC456F5B793EAFAE5C9E1DC182575D
HistoryMar 24, 2020 - 12:23 p.m.

Security Bulletin: Security vulnerability is identified in Apache POI server where Rational Asset Manager is deployed (CVE-2019-12415)

2020-03-2412:23:08
www.ibm.com
12

0.001 Low

EPSS

Percentile

40.7%

Summary

The Apache POI that is bundled along with Rational Asset Manager has a potential security vulnerability, which could be exploited by a remote attacker to obtain sensitive information. Respective security vulnerabilities are discussed in detail in the subsequent sections.

Vulnerability Details

CVEID:CVE-2019-12415
**DESCRIPTION:**Apache POI could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data by tool XSSFExportToXml. By sending a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/170015 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Rational Asset Manager 7.5.4.3

Remediation/Fixes

You must upgrade to the Rational Asset Manager 7.5.4.3 interim fix or Download the iFix specified in the following table and apply it.

Version Fix
Rational Asset Manager 7.5.4.3 Rational Asset Manager 7.5.4.3 iFix Download.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

40.7%

Related for 57F776FF55271032943DDA94EDAE416CC0AC456F5B793EAFAE5C9E1DC182575D