Lucene search

K
ibmIBM6D72F5E2F90CAC5A4D151DD3483103FAB60A4A6FCD9FF4EB47E5E45ACF7A4129
HistoryMar 08, 2021 - 5:36 p.m.

Security Bulletin: Vulnerability in FasterXML Jackson libraries affect IBM Cúram Social Program Management (CVE-2020-25649)

2021-03-0817:36:38
www.ibm.com
18

0.004 Low

EPSS

Percentile

72.5%

Summary

IBM Cúram Social Program Management uses the FasterXML Jackson libraries, for which there is a publicly known vulnerability. For this vulnerability FasterXML Jackson Databind could provide weaker than expected security, caused by not having entity expansion secured properly.

Vulnerability Details

CVEID:CVE-2020-25649
**DESCRIPTION:**FasterXML Jackson Databind could provide weaker than expected security, caused by not having entity expansion secured properly. A remote attacker could exploit this vulnerability to launch XML external entity (XXE) attacks to have impact over data integrity.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/192648 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Curam SPM 7.0.10 - 7.0.11
Curam SPM 7.0.5 - 7.0.9

Remediation/Fixes

Product VRMF Remediation/First Fix
Cúram SPM

7.0.11

| Visit IBM Fix Central and upgrade to 7.0.11_iFix2 or a subsequent 7.0.11 release.
Cúram SPM|

7.0.9

| Visit IBM Fix Central and upgrade to 7.0.9.0_iFix7 or a subsequent 7.0.4 release.

Workarounds and Mitigations

For information about all other versions, contact IBM Cúram Social Program Management customer support.