Lucene search

K
ibmIBM6F00ABE4CAE86046BA6F8DB98B699B35E1576BA3A41DF2CF932EECB6C3DA34B0
HistoryJul 13, 2020 - 8:36 p.m.

Security Bulletin: Apache Tika as used by IBM QRadar SIEM is vulnerable to a denial of service (CVE-2020-1951, CVE-2020-1950)

2020-07-1320:36:32
www.ibm.com
8

EPSS

0.001

Percentile

23.6%

Summary

Apache Tika as used by IBM QRadar SIEM is vulnerable to a denial of service

Vulnerability Details

CVEID:CVE-2020-1951
**DESCRIPTION:**Apache Tika is vulnerable to a denial of service, caused by an error in the PSDParser. By persuading a victim to open a specially-crafted PSD file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/178089 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID:CVE-2020-1950
**DESCRIPTION:**Apache Tika is vulnerable to a denial of service, caused by an excessive memory usage flaw in the PSDParser. By persuading a victim to open a specially-crafted PSD file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/178088 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM QRadar SIEM 7.4.0 to 7.4.0 Patch 2

IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 3

Remediation/Fixes

QRadar / QRM / QVM / QRIF / QNI 7.4.0 Patch 3

QRadar / QRM / QVM / QRIF / QNI 7.3.3 Patch 4

Workarounds and Mitigations

None

EPSS

0.001

Percentile

23.6%