Lucene search

K
ibmIBM998BC9B439E50796891982055C692395921E928701C0F4D9B2036843905A6302
HistoryAug 31, 2020 - 2:28 p.m.

Security Bulletin: IBM Security Privileged Identity Manager is affected by security vulnerabilities

2020-08-3114:28:37
www.ibm.com
15
ibm security
privileged identity manager
vulnerability
cve-2019-11745
nss
mozilla firefox
remote attacker
execute arbitrary code
denial of service
heap corruption
cvss base score
cvss temporal score
cvss vector
affected products
versions
ispim 2.0.2
ispim 2.1.0
remediation
2.1.0-iss-ispim-va-fp0012
2.0.2-iss-ispim-va-fp0013

EPSS

0.003

Percentile

69.1%

Summary

IBM Security Privileged Identity Manager has addressed an issue for nss-softokn as follows.

Vulnerability Details

CVEID:CVE-2019-11745
**DESCRIPTION:**Mozilla Network Security Services (NSS), as used in Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write when encrypting with a block cipher. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to corrupt the heap and execute arbitrary code on the vulnerable system or cause a denial of service.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/172458 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ISPIM 2.0.2
ISPIM 2.1.0

Remediation/Fixes

Affected Product(s) Version(s) Remediation
ISPIM 2.1.0 2.1.0-ISS-ISPIM-VA-FP0012
ISPIM 2.0.2 2.0.2-ISS-ISPIM-VA-FP0013

Workarounds and Mitigations

None