Lucene search

K
ibmIBM78879236E608FC893E9368B37AB9F262049B5D56217CF5813FD892962F40ED95
HistoryMay 20, 2021 - 6:59 p.m.

Security Bulletin: A security vulnerabilitiy has been fixed in IBM Security Identity Manager Virtual Appliance(CVE-2019-17006)

2021-05-2018:59:37
www.ibm.com
14

0.004 Low

EPSS

Percentile

73.6%

Summary

IBM Security Identity Manager Virtual Appliance (ISIM VA) has addressed the following vulnerabilitiy in various Open Source packages:

Vulnerability Details

CVEID:CVE-2019-17006
**DESCRIPTION:**Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when using certain cryptographic primitives. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174125 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ISIM VA 7.0.2

Remediation/Fixes

Affected Product(s) Version(s) Fix Availability
IBM Security Identity Manager Virtual Appliance 7.0.2 7.0.2-ISS-SIM-FP0003

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security identity managereq7.0.2