Lucene search

K
ibmIBM867F57E644CA0B9EBAE8F6B4AF3E43E47039153C5F0CFE46A8DE2A9C5715A892
HistoryMar 31, 2020 - 2:56 a.m.

Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in jackson-databind

2020-03-3102:56:38
www.ibm.com
12

0.006 Low

EPSS

Percentile

79.0%

Summary

IBM Watson Discovery for IBM Cloud Pak for Data has a vulnerable version of FasterXML jackson-databind. A flaw was discovered in FasterXML jackson-databind, where it would permit polymorphic deserialization of malicious objects.

Vulnerability Details

CVEID:CVE-2019-20330
**DESCRIPTION:**A lacking of certain net.sf.ehcache blocking in FasterXML jackson-databind has an unknown impact and attack vector.
CVSS Base score: 7.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/173897 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
ICP - Discovery 2.0.0-2.1.1

Remediation/Fixes

Upgrade to IBM Watson Discovery 2.1.2

<https://www.ibm.com/support/knowledgecenter/SSQNUZ_2.5.0/cpd/svc/watson/discovery-install.html&gt;

Workarounds and Mitigations

None

0.006 Low

EPSS

Percentile

79.0%