Lucene search

K
ibmIBM6ED6AB071FF278905E27EAB23B71E701DE6BB6552A58CBDC6C3ACD27D51AB470
HistoryMar 29, 2022 - 10:53 p.m.

Security Bulletin: An vulnerability in 3rd party library jackson-databind affect IBM Spectrum LSF Suite, IBM Spectrum LSF Explorer and IBM Platform Application Center

2022-03-2922:53:26
www.ibm.com
20

0.002 Low

EPSS

Percentile

60.1%

Summary

There is an vulnerability(CVE-2020-36518) in in 3rd party library jackson-databind affect IBM Spectrum LSF Suite, IBM Spectrum LSF Explorer and IBM Platform Application Center,

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum LSF Explorer

10.2.0.x

(x <=12)

IBM Platform Application Center|

10.2.0.x

(x <=12)

IBM Spectrum LSF Suite|

10.2.0.x

(x <=12)

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation/First Fix

—|—|—|—

IBM Spectrum LSF Suite

IBM Platform Application Center

IBM Spectrum LSF Explorer

|

10.2.0.x

(x <=12)

|

None

|

  1. Download jackson-databind-2.12.6.jar, jackson-core-2.12.6 .jar, jackson-annotations-2.12.6 .jar jackson-jaxrs-base-2.12.6 .jar , jackson-jaxrs-json-provider-2.12.6 .jar, jackson-module-jaxb-annotations-2.12.6 .jar from: https://mvnrepository.com/artifact/com.fasterxml.jackson.core/ ,
  2. Copy the package into the Application Center host.
  3. On the Application Center host, stop pmc service by “pmcadmin stop”
  4. On the Application Center host, replace jackson--2.10.0.jar and jackson--2.9.2.jar with new jar jackson-*-2.12.6.jar.

cd $GUI_TOP/

find . -name “jackson-*”

./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-annotations-2.10.0.jar
./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-core-2.10.0.jar
./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-databind-2.10.0.jar
./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-jaxrs-base-2.10.0.jar
./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-jaxrs-json-provider-2.10.0.jar
./3.0/wlp/usr/servers/platform/apps/platform.war/WEB-INF/lib/jackson-module-jaxb-annotations-2.10.0.jar
./3.0/wlp/usr/servers/notification/apps/notification.war/WEB-INF/lib/jackson-annotations-2.9.2.jar
./3.0/wlp/usr/servers/notification/apps/notification.war/WEB-INF/lib/jackson-core-2.9.2.jar
./3.0/wlp/usr/servers/notification/apps/notification.war/WEB-INF/lib/jackson-databind-2.9.2.jar

5. On the Application Center host, start pmc service by “pmcadmin start”.

Workarounds and Mitigations

the issue will be fixed in next fix patch release FP13 in Q2