Lucene search

K
ibmIBM5E20752A27AB58A1F4D84B7E14AE23C5DC19B3C161E9CA4ED5DA50124F63AEC0
HistoryMay 14, 2021 - 1:37 a.m.

Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in FasterXML jackson-dataformat

2021-05-1401:37:34
www.ibm.com
6

0.001 Low

EPSS

Percentile

44.4%

Summary

IBM Watson Discovery for IBM Cloud Pak for Data contains a vulnerable version of FasterXML jackson-dataformat.

Vulnerability Details

CVEID:CVE-2020-28491
**DESCRIPTION:**FasterXML jackson-dataformats-binary is vulnerable to a denial of service, caused by an unchecked allocation of byte buffer flaw. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a java.lang.OutOfMemoryError exception resulting in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/197038 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ICP - Discovery 2.0.0-2.2.1

Remediation/Fixes

Upgrade to IBM Watson Discovery 2.2.1 and apply 2.2.1 patch-2

<https://cloud.ibm.com/docs/discovery-data?topic=discovery-data-install&gt;

<https://www.ibm.com/support/pages/available-patches-watson-discovery-ibm-cloud-pak-data&gt;

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

44.4%

Related for 5E20752A27AB58A1F4D84B7E14AE23C5DC19B3C161E9CA4ED5DA50124F63AEC0