Lucene search

K
ibmIBM8FFBF7DE9729E38A1978C390480A0C3FEF3586A454B2C41C95E9BD2494A959A2
HistoryJan 28, 2021 - 12:49 p.m.

Security Bulletin: Apache Commons Configuration Vulnerability Affects IBM Control Center (CVE-2020-1953)

2021-01-2812:49:29
www.ibm.com
9

0.006 Low

EPSS

Percentile

79.3%

Summary

Apache Commons Configuration is vulnerable to remote attack.

Vulnerability Details

CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Control Center 6.2.0.0

Remediation/Fixes

Product|

VRMF

|

iFix

|

Remediation

—|—|—|—

IBM Control Center

|

6.2.0.0

|

iFix05

|

Fix Central - 6.2.0.0

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm control centereq6.2.0.0

0.006 Low

EPSS

Percentile

79.3%

Related for 8FFBF7DE9729E38A1978C390480A0C3FEF3586A454B2C41C95E9BD2494A959A2