Lucene search

K
ibmIBMA743ED07DD073D5B4C5C08D95ABD4065D1295029D33C7A39288EFE0EED632C4B
HistoryJun 16, 2018 - 2:17 p.m.

Security Bulletin: IBM Streams may be affected by XMLsoft Libxml2 vulnerabilities

2018-06-1614:17:48
www.ibm.com
12

0.022 Low

EPSS

Percentile

89.4%

Summary

The libxml2 library, used by IBM Streams may have security vulnerabilities. IBM Streams has addressed the applicable CVE.

Vulnerability Details

CVE-ID: CVE-2015-8806
Description: Libxml2 is vulnerable to a denial of service, caused by a heap-buffer overread in dict.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 4.300
CVSS Temporal Score: <https://exchange.xforce.ibmcloud.com/vulnerabilities/110613&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

The following versions may be impacted:

  • IBM Streams Version 4.2.1.2 and earlier
  • IBM InfoSphere Streams Version 4.1.1.4 and earlier
  • IBM InfoSphere Streams Version 4.0.1.4 and earlier
  • IBM InfoSphere Streams Version 3.2.1.6 and earlier
  • IBM InfoSphere Streams Version 3.1.0.8 and earlier
  • IBM InfoSphere Streams Version 3.0.0.6 and earlier

Remediation/Fixes

NOTE: Fix Packs are available on IBM Fix Central.

To remediate/fix this issue, follow the instructions below:

  • Version 4.2.x: Apply 4.2.1 Fix Pack 3 (4.2.1.3) or higher.
  • Version 4.1.x: Apply 4.1.1 Fix Pack 5 (4.1.1.5) or higher.
  • Version 4.0.x: Apply 4.0.1 Fix Pack 5 (4.0.1.5) or higher.
  • Versions 3.2.x, 3.1.x, and 3.0.x: For versions earlier than 4.x.x, IBM recommends upgrading to a fixed, supported version/release/platform of the product. Customers who cannot upgrade and need to secure their installation should open a PMR with IBM Technical Support and request assistance securing their InfoSphere Streams system against the vulnerabilities identified in this Security Bulletin.

Workarounds and Mitigations

None

0.022 Low

EPSS

Percentile

89.4%