Lucene search

K
ibmIBMA7E5A7C361A019164A7518965CF181FF695F0B51C82892959F92F5B981B722D2
HistoryApr 08, 2021 - 8:59 p.m.

Security Bulletin: Infosphere BigInsights is affected by a vulnerability in DB2 (CVE-2014-0919).

2021-04-0820:59:42
www.ibm.com
16
infosphere biginsights
db2
vulnerability disclosure

EPSS

0.002

Percentile

57.6%

Summary

Infosphere BigInsights is affected by vulnerability in DB2 that can lead to user ID and password/cipher exposure (CVE-2014-0919). The vulnerability exists in the Big SQL server component included in BigInsights.

Vulnerability Details

CVEID: CVE-2014-0919**
DESCRIPTION:** IBM DB2 contains a vulnerability that would allow an authenticated user to execute a series of commands that would disclose the user name and password of users of the federated data servers and services.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91981 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N)

Affected Products and Versions

IBM InfoSphere BigInsights: 3.0, 3.0.0.1, 3.0.0.2, 4.0

Remediation/Fixes

For affected versions, apply the interim fix from Fix Central by following instructions in Readme.

BigInsights Version Fix Central Link to DB2 installable image Readme
3.0 / 3.0.0.1 3.0 / 3.0.0.1 Build BigInsights 3.0.0.1 Readme for CVE-2014-0919 .docxBigInsights 3.0.0.1 Readme for CVE-2014-0919 .docx
3.0.0.2 3.0.0.2 Build BigInsights 3.0.0.2 Readme for CVE-2014-0919 .docxBigInsights 3.0.0.2 Readme for CVE-2014-0919 .docx
4.0 4.0 Build BigInsights 4.0 Readme for CVE-2014-0919 .docxBigInsights 4.0 Readme for CVE-2014-0919 .docx

EPSS

0.002

Percentile

57.6%

Related for A7E5A7C361A019164A7518965CF181FF695F0B51C82892959F92F5B981B722D2