Lucene search

K
ibmIBM8B055C715D9EDDBF8CFD0F8FE80E19022033ED5A062A0CD2549C8B53D6F214C8
HistoryJun 16, 2018 - 9:45 p.m.

Security Bulletin: IBM Security Access Manager version 9 is affected by a vulnerability in postgreSQL (CVE-2015-5288)

2018-06-1621:45:08
www.ibm.com
13

0.028 Low

EPSS

Percentile

90.7%

Summary

A vulnerability in postgreSQL affects IBM Security Access Manager version 9.

Vulnerability Details

CVEID: CVE-2015-5288**
DESCRIPTION:** PostgreSQL could allow a remote attacker to obtain sensitive information, caused by an error in the crypt() function included with the optional pgCrypto extension. By sending specially-crafted data, a remote attacker could exploit this vulnerability to read portions of memory.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/107026 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Access Manager 9.0, all firmware versions

Remediation/Fixes

Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager 9.0 IV86697 1. For versions prior to 9.0.1.0, upgrade to 9.0.1.0:
IBM Security Access Manager V9.0.1 Multiplatform, Multilingual (CRW4EML)
2. Apply 9.0.1.0 Interim Fix 2:
9.0.1.0-ISS-ISAM-IF0002

Workarounds and Mitigations

None.