Lucene search

K
ibmIBM752DDB784CBC3847FB15605BACB859E282F27F5D35B885972A2C5CDE474CE53E
HistoryJan 14, 2022 - 12:14 p.m.

Security Bulletin: Vulnerability exists in Watson Explorer (CVE-2021-22096)

2022-01-1412:14:09
www.ibm.com
21
ibm watson explorer
security vulnerability
cve-2021-22096
spring framework
deep analytics edition
foundational components
analytical components
upgrade
version 12.0.3.9
version 11.0.2.13

EPSS

0.001

Percentile

34.2%

Summary

Security vulnerability in Spring Framework affects IBM Watson Explorer. IBM Watson Explorer has addressed the vulnerability.

Vulnerability Details

CVEID:CVE-2021-22096
**DESCRIPTION:**VMware Spring Framework could allow a remote attacker to bypass security restrictions. By sending a specially-crafted input, an attacker could exploit this vulnerability to cause the insertion of additional log entries.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/212430 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Explorer Deep Analytics Edition Foundational Components

12.0.0.0,

12.0.1,

12.0.2.0 - 12.0.2.2,

12.0.3.0 - 12.0.3.8

IBM Watson Explorer Deep Analytics Edition Analytical Components|

12.0.0.0,

12.0.1,

12.0.2.0 - 12.0.2.2,

12.0.3.0 - 12.0.3.8

IBM Watson Explorer Foundational Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 - 11.0.2.12
IBM Watson Explorer Analytical Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 - 11.0.2.12

Remediation/Fixes

Affected Product Affected Versions How to acquire and apply the fix
IBM Watson Explorer Deep Analytics Edition
Foundational Components

12.0.0.0,

12.0.1,

12.0.2.0 - 12.0.2.2, 12.0.3.0 - 12.0.3.8

|

Upgrade to Version 12.0.3.9.

See Watson Explorer Version 12.0.3.9 Foundational Components for download information and instructions.

IBM Watson Explorer Deep Analytics Edition Analytical Components| 12.0.0.0, 12.0.1, 12.0.2.0 - 12.0.2.2, 12.0.3.0 - 12.0.3.8|

Upgrade to Version 12.0.3.9.

See Watson Explorer Version 12.0.3.9 Analytical Components for download information and instructions.

IBM Watson Explorer
Foundational Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 -
11.0.2.12|

Upgrade to Version 11.0.2.13.

See Watson Explorer Version 11.0.2.13 Foundational Components for download information and instructions.

IBM Watson Explorer Analytical Components| 11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2.0 -
11.0.2.12|

Upgrade to Version 11.0.2.13.

See Watson Explorer Version 11.0.2.13 Analytical Components for download information and instructions.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

34.2%

Related for 752DDB784CBC3847FB15605BACB859E282F27F5D35B885972A2C5CDE474CE53E