Lucene search

K
ibmIBM8BA925E4FA1047E895B91E2EE5AC149982EE463DECBC5C2689B2B66BF32EAC25
HistorySep 22, 2021 - 11:38 p.m.

Security Bulletin: Vulnerability in libssh2 CVE-2019-17498.

2021-09-2223:38:15
www.ibm.com
12

0.004 Low

EPSS

Percentile

73.9%

Summary

libssh2 is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2019-17498
**DESCRIPTION:**libssh2 is vulnerable to a denial of service, caused by an out-of-bounds read when connecting to a malicious SSH server that sends a disconnect message. A remote attacker could exploit this vulnerability to cause a denial of service or obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169461 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
HMC V9.1.910.0 V9.1.910.0

Remediation/Fixes

Remediation/Fixes

The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/&gt;

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V9.1.940.0 SP2 ppc

|

MB04269

|

MH01877

Power HMC

|

V9.1.940.0 SP2 x86_64

|

MB04268

|

MH01876

Workarounds and Mitigations

None