Lucene search

K
ibmIBM79A57DCA9547EB7144EF1FD539121D0ABCED0FDC7C53893D2995C5C2A1DAAA8A
HistoryJun 11, 2020 - 3:59 p.m.

Security Bulletin: IBM Event Streams is affected by kafka vulnerability CVE-2019-12399

2020-06-1115:59:18
www.ibm.com
10

EPSS

0.001

Percentile

48.2%

Summary

IBM Event Streams has addressed the following vulnerability

Vulnerability Details

CVEID:CVE-2019-12399
**DESCRIPTION:**Apache Kafka could allow a remote attacker to obtain sensitive information, caused by a flaw in the Connect REST API. By sending specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information in tasks endpoint.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174387 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 2019.2.1

IBM Event Streams in IBM Cloud Pak for Integration

|

2019.2.2

IBM Event Streams in IBM Cloud Pak for Integration

|

2019.2.3

IBM Event Streams

|

2019.4.1

IBM Event Streams in IBM Cloud Pak for Integration

| 2019.4.1

Remediation/Fixes

Upgrade from IBM Event Streams 2019.2.1 to IBM Event Streams 2019.4.1 by downloading IBM Event Streams 2019.4.1 from IBM Passport Advantage.

Upgrade from IBM Event Streams 2019.4.1 to the latest Fix Pack.

Upgrade IBM Event Streams 2019.2.2, IBM Event Streams 2019.2.3 and IBM Event Streams 2019.4.1 in IBM Cloud Pak for Integration by downloading IBM Event Streams 2019.4.2 in IBM Cloud Pak for Integration 2020.2.1 from IBM Passport Advantage.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

48.2%

Related for 79A57DCA9547EB7144EF1FD539121D0ABCED0FDC7C53893D2995C5C2A1DAAA8A