Vulnerabilities in Open Source Python affect IBM Tivoli Application Dependency Discovery Manager
CVEID: CVE-2016-5699**
DESCRIPTION:** urllib2 and urllib for Python are vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114200 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2016-5636**
DESCRIPTION:** zipimport module for Python is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the get_data() function in zipimport.c. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114309 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
TADDM 7.2.2.0 - 7.2.2.5
TADDM 7.3.0.0 - 7.3.0.3
There are eFixes prepared on top of the latest released FixPack for each stream:
Fix | VRMF | APAR | How to acquire fix |
---|---|---|---|
efix_TADDM73_jython21_FP320160323.zip | 7.3.0.3 | None | Download eFix |
efix_TADDM722_jython21_FP520160209.zip | 7.2.2.5 | ||
None | Download eFix |
Please get familiar with eFix readme in etc/<efix_name>_readme.txt
None
CPE | Name | Operator | Version |
---|---|---|---|
tivoli application dependency discovery manager | eq | 7.2.2 | |
tivoli application dependency discovery manager | eq | 7.3 |