Lucene search

K
ibmIBMB1880020491708C5FB008A49E9E8587F01FF63635806382D18F5AF4768F10A66
HistoryJun 16, 2018 - 8:03 p.m.

Security Bulletin: IBM Forms Server may be affected by an Apache Xerces-C XML Parser library vulnerability (CVE-2016-0729, CVE-2016-4463)

2018-06-1620:03:35
www.ibm.com
16

EPSS

0.024

Percentile

90.1%

Summary

An IBM Form (XFDL document) that contains a specially crafted mark-up could crash IBM Forms Server. This may expose a vulnerability in its use of the Apache Xerces-C XML Parser library.

Vulnerability Details

CVEID: CVE-2016-0729**
DESCRIPTION:** Apache Xerces-C XML Parser library is vulnerable to a denial of service, caused by improper bounds checking during processing and error reporting. By sending specially crafted input documents, an attacker could exploit this vulnerability to cause the library to crash or possibly execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111028 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-4463**
DESCRIPTION:** Apache Xerces-C XML Parser library is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing a deeply nested DTD. A remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114596 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM Forms Server 8.0.1
IBM Forms Server 8.1
IBM Forms Server 8.2
IBM Forms Server 8.2.1

Remediation/Fixes

** Product**

| VRMF|** APAR**|** Remediation**
—|—|—|—
IBM Forms Server| 8.0.1.| LO89918| Download fix LO89918 and apply to the files specified in the included instructions.
IBM Forms Server| 8.1.
| LO89918| Download fix LO89918 and apply to the files specified in the included instructions.
IBM Forms Server| 8.2.*| LO89918| Download fix LO89918 and update all application with this new version of the Forms API

Workarounds and Mitigations

None