A vulnerability was found in Oniguruma 6.9.2 that would result in a NULL Pointer Dereference, affecting IBM Cloud Pak for Applications
CVEID:CVE-2019-13225
**DESCRIPTION:**oniguruma is vulnerable to a denial of service, caused by a NULL pointer dereference in match_at() in regexec.c. By persuading a victim to compile a specially crafted file and execute its object code, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/166874 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Affected Product(s) | Version(s) |
---|---|
IBM Cloud Pak for Applications | All |
IBM Cloud Pak for Applications 4.3.1 uses an updated version of Oniguruma which no longer exposes this vulnerability. No separate APAR is provided.
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm cloud pak for applications | eq | any |