Lucene search

K
ibmIBMC26C11BE05ACD8A2C83F0DB7B1892810A051510E92DBA86C9AF94113E6A66789
HistoryJan 13, 2021 - 5:58 p.m.

Security Bulletin: IBM MaaS360 Cloud Extender has security vulnerabilities (CVE-2020-1155, CVE-2020-1156)

2021-01-1317:58:33
www.ibm.com
40

0.016 Low

EPSS

Percentile

87.7%

Summary

A vulnerability was identified and remediated in the IBM MaaS360 Cloud Extender

Vulnerability Details

CVEID:CVE-2020-11656
**DESCRIPTION:**SQLite could allow a remote attacker to obtain sensitive information, caused by a use-after-free in the ALTER TABLE implementation. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information and then use this information to launch further attacks against the affected system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/180285 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2020-11655
**DESCRIPTION:**SQLite is vulnerable to a denial of service, caused by mishandling the AggInfo object’s initialization. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a segmentation fault.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/180289 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MaaS360 Cloud Extender 2.101.x and prior

Remediation/Fixes

Update the IBM MaaS360 Cloud Extender to version 2.102.000.060 or greater.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm maas360eq360
ibm maas360eq2.101