Lucene search

K
ibmIBM7275D516589DC63B030EC49F38045C03E863DD1B9A1D63C8F15E13153DCEE21E
HistoryJun 17, 2018 - 12:19 p.m.

Security Bulletin: IBM Content Navigator is affected by a common separated value (CSV) vulnerability

2018-06-1712:19:14
www.ibm.com
10

0.001 Low

EPSS

Percentile

27.0%

Summary

IBM Content Navigator has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2018-1366**
DESCRIPTION: *IBM Content Navigator is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software.
CVSS Base Score: 4.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/137452 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected IBM Content Navigator

|

Affected Versions

—|—
IBM Content Navigator| 2.0.3.7 - 2.0.3.8
IBM Content Navigator| 3.0.0 - 3.0.3

Remediation/Fixes

Product

|

VRMF

|

Remediation / First Fix

—|—|—
IBM Content Navigator| 2.0.3.7 - 2.0.3.8| Contact customer support center for the fix and instructions.
IBM Content Navigator| 3.0.0 - 3.0.3| Contact customer support center for the fix and instructions.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

27.0%

Related for 7275D516589DC63B030EC49F38045C03E863DD1B9A1D63C8F15E13153DCEE21E