Lucene search

K
ibmIBMA69098E9BE94AD68721C67F614DAC5FBBD49D81766E845C602E410511AA06C2A
HistoryJun 17, 2018 - 12:17 p.m.

Security Bulletin: Open Source Apache PDFBox Vulnerability in IBM eDiscovery Analyzer

2018-06-1712:17:04
www.ibm.com
12

0.001 Low

EPSS

Percentile

39.2%

Summary

Apache PDFBox could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.

Vulnerability Details

CVEID: CVE-2016-2175 DESCRIPTION: Apache PDFBox could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/113548 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S)

Affected Products and Versions

IBM eDiscovery Analyzer 2.2.2

Remediation/Fixes

Product

| VRM|Remediation
—|—|—
IBM eDiscovery Analyzer 2.2.2| 2.2.2| Use IBM eDiscovery Analyzer 2.2.2 Interim Fix 0004

Workarounds and Mitigations

NA

CPENameOperatorVersion
ediscovery analyzereq2.2.2

0.001 Low

EPSS

Percentile

39.2%

Related for A69098E9BE94AD68721C67F614DAC5FBBD49D81766E845C602E410511AA06C2A