Lucene search

K
ibmIBMAA6BF2EA9C16110B1B01E073FE5CEF113CF85F6E8C8E215791B694C5041A5B6A
HistoryAug 22, 2019 - 7:09 p.m.

Security Bulletin: Remote Execution Vulnerability Affects Red Hat Linux Used By IBM WebSphere Application Server for IBM Cloud Private VM Quickstarter (CVE-2019-12735)

2019-08-2219:09:52
www.ibm.com
11

0.004 Low

EPSS

Percentile

74.1%

Summary

There is a security vulnerability that affects Red Hat Linux used by IBM WebSphere Application Server in the IBM Cloud.

Vulnerability Details

Relevant CVE Information:

CVEID: CVE-2019-12735 DESCRIPTION: Vim and and Neovim could allow a remote attacker to execute arbitrary commands on the system, caused by improper input validation by the :source! command in a modeline. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base Score: 9.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/162255&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

These vulnerabilities affect the following versions and releases of IBM WebSphere Application Server for IBM Cloud Private VM Quickstarter:

  • 2.0
  • 3.0

Remediation/Fixes

To mitigate the vulnerability on an existing service instance issue the following command as root:

  • echo “set nomodeline” >> /etc/vimrc

To obtain these changes for your installation, upgrade IBM WebSphere Application Server for IBM Cloud Private VM Quickstarter to version 3.0.100 or higher. The service procedure can be found here: