Lucene search

K
ibmIBMAD4B1AAFD44E83526C8743090B14C5358C50143FDAD6C7222E21D3F6506B6C57
HistoryMar 11, 2019 - 1:35 p.m.

Security Bulletin: A Security Vulnerability affects IBM Cloud Private Service Catalog

2019-03-1113:35:01
www.ibm.com
10

0.002 Low

EPSS

Percentile

56.7%

Summary

A Security Vulnerability affects IBM Cloud Private Service Catalog

Vulnerability Details

CVEID: CVE-2018-10904 DESCRIPTION: glusterfs could allow a remote authenticated attacker to execute arbitrary code on the system, caused by improper validation of file paths in the trusted.io-stats-dump extended attribute. By sending a specially-crafted request, an attacker could exploit this vulnerability to create files and execute arbitrary code on the system.
CVSS Base Score: 8.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/149295&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM Cloud Private 3.1.1

Remediation/Fixes

IBM Cloud Private 3.1.1 patch - Available in Fix Central

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud privateeq3.1.1

0.002 Low

EPSS

Percentile

56.7%