Lucene search

K
ibmIBMBE6E59EC7174BAE5328A109B3746360DD0DA9EEC148E843FA99652922A32EE77
HistoryJun 17, 2018 - 6:07 a.m.

Security Bulletin: Multi-Cloud Data Encryption (MDE) is using components with Known Vulnerabilities

2018-06-1706:07:21
www.ibm.com
9

0.045 Low

EPSS

Percentile

92.5%

Summary

Multi-Cloud Data Encryption (MDE) has addressed the following vulnerability: Using components with known vulnerabilities

Vulnerability Details

CVEID:CVE-2017-5637**
DESCRIPTION: *Apache Zookeeper is vulnerable to a denial of service, caused by the improper handling of the wchp command. By sending a specially-crafted wchp command, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/121602 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Multi-Cloud Data Encryption (MDE)

|

Affected Versions

—|—
IBM Multi-Cloud Data Encryption| 2.1 - 2.1.0.2

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation / First Fix

—|—|—|—
IBM Multi-Cloud Data Encryption| 2.2.0.0| N/A| IBM Multi-Cloud Data Encryption V2.2.0.0 Multiplatform English (CJ3LPEN) via Passport Advantage: <https://www-01.ibm.com/software/passportadvantage/pao_customer.html&gt;

Workarounds and Mitigations

Manually upgrade the ZooKeeper component to at least version 3.4.10.

CPENameOperatorVersion
ibm multi-cloud data encryptioneq2.1

0.045 Low

EPSS

Percentile

92.5%