Lucene search

K
ibmIBM792B85A8DB94781D66D2F4C4B62AF0AB0D8345DE0EDC163D9DF3146450CB58F8
HistoryJun 21, 2021 - 11:05 p.m.

Security Bulletin: IBM InfoSphere Information Server is affected by a vulnerability in Apache httpclient

2021-06-2123:05:12
www.ibm.com
20

0.002 Low

EPSS

Percentile

53.1%

Summary

A vulnerability in Apache httpclient used by IBM InfoSphere Information Server was addressed.

Vulnerability Details

CVEID:CVE-2020-13956
**DESCRIPTION:**Apache HttpClient could allow a remote attacker to bypass security restrictions, caused by the improper handling of malformed authority component in request URIs. By passing request URIs to the library as java.net.URI object, an attacker could exploit this vulnerability to pick the wrong target host for request execution.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189572 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Information Server 11.7
InfoSphere Information Server 11.5

Remediation/Fixes

Product VRMF APAR Remediation/First Fix
InfoSphere Information Server, Information Server on Cloud 11.7 JR62184
--Apply InfoSphere Information Server version 11.7.1.0
--Apply InfoSphere Information Server version 11.7.1.0 Fix Pack 1
--Apply InfoSphere Information Server 11.7.1.1 Service Pack 1
--Download and install the latest version of ISALite
--Apply Data Quality Exception console security patch

For Red Hat 8 installations, contact IBM Customer support.
InfoSphere Information Server, Information Server on Cloud | 11.5 | JR62184
| --Upgrade to a release where the issue is addressed

Contact Technical Support:

In the United States and Canada dial 1-800-IBM-SERV
View the support contacts for other countries outside of the United States.
Electronically open a Service Request with Information Server Technical Support.

Workarounds and Mitigations

None