Lucene search

K
ibmIBM941628724EECFA402D377A82238DB662B1164AAD96172968EBCACDE331203F80
HistoryDec 03, 2018 - 9:00 p.m.

Security Bulletin: Apache PDFBox as used in IBM QRadar Incident Forensics is vulnerable to Publicly disclosed vulnerability. (CVE-2018-8036)

2018-12-0321:00:01
www.ibm.com
9

0.007 Low

EPSS

Percentile

79.7%

Summary

Publicly disclosed vulnerability in Apache PDFBox.

Vulnerability Details

CVEID: CVE-2018-8036
**Description:**Apache PDFBox is vulnerable to a denial of service, caused by an out of memory exception in AFMParser. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
**CVSS Base Score:**5.50
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/145592&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products and Versions

IBM QRadar Incident Forensics 7.2.0 to 7.2.8 Patch 13

IBM QRadar Incident Forensics 7.3.0 to 7.3.1 Patch 6

Remediation/Fixes

QRadar / QRM / QVM / QRIF / QNI 7.2.8 Patch 14

QRadar / QRM / QVM / QRIF / QNI 7.3.1 Patch 7

Workarounds and Mitigations

None

0.007 Low

EPSS

Percentile

79.7%