Lucene search

K
ibmIBM8857F05BB1AEC4114159FCD9C6C498B4EFC19623C98F261F15E377281493E3E1
HistoryNov 10, 2020 - 10:36 a.m.

Security Bulletin: Vulnerability in Oracle Java SE and libjpeg affects IBM Integrated Analytics System

2020-11-1010:36:53
www.ibm.com
23
oracle java se
libjpeg
ibm integrated analytics system
vulnerability
cve-2018-11212
cve-2019-2422
denial of service
remote attacker
crash
sensitive information
confidentiality impact
fix central

EPSS

0.007

Percentile

79.8%

Summary

Redhat provided Oracle Java SE and libjpeg package is used by IBM Integrated Analytics System. IBM Integrated Analytics System has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2018-11212
**DESCRIPTION:**libjpeg is vulnerable to a denial of service, caused by divide-by-zero error in the alloc_sarray function in jmemmgr.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/143429 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID:CVE-2019-2422
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE related to the Java SE Libraries component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/155741 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Integrated Analytics System 1.0.0-1.0.23.0

Remediation/Fixes

Product VRMF Remediation / First Fix
IBM Integrated Analytics System 1.0.24.0 Link_to_Fix_Central

Workarounds and Mitigations

None