Lucene search

K
ibmIBM64A39B51D68C2DF24994E70632A3F2E3872FF3B94659063E70F24747C28D0EE4
HistoryDec 20, 2019 - 8:47 a.m.

Security Bulletin: One vulnerability of Mozzila Firefox (less than Firefox 60.7.2 ESR) has affected Synthetic Playback Agent 8.1.4.0 - 8.1.4 IF07

2019-12-2008:47:33
www.ibm.com
13

0.008 Low

EPSS

Percentile

82.0%

Summary

Synthetic Playback Agent has addressed the following vulnerabilities: CVE-2019-11708

Vulnerability Details

CVEID:CVE-2019-11708
**DESCRIPTION:**Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user’s computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/162774 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
APM SaaS 8.1.4
APM AM 8.1.4
BAM 1.0
APM on-premise 8.1.4

Remediation/Fixes

Product Remediation / Fix
APM on-premise Synthetic Playback Agent 8.1.4 IF10

Workarounds and Mitigations

None