Lucene search

K
ibmIBMC4E8C0A9E87715D0D21F35FA0255164F3C3E6AE2F4D8F9089E40962ACAB2C78E
HistoryJul 01, 2019 - 5:40 p.m.

Security Bulletin: vulnerability in urllib3 library embedded into Tensorboard PowerAI CVE-2019-11324

2019-07-0117:40:01
www.ibm.com
8

0.004 Low

EPSS

Percentile

74.4%

Summary

The urllib3 1.24.1 library mishandles SSL connections in certain cases where a verification failure is the correct outcome. This library version is embedded into Tensorboard 1.13, which is included in PowerAI 1.6.0.

Vulnerability Details

Vulnerability Details
CVEID: CVE-2019-11324

DESCRIPTION
The urllib3 library mishandles certain cases which results in SSL connections succeeding in situations where a verification failure is the correct outcome.

CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/159909 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

PowerAI 1.6.0

Remediation/Fixes

Fix Version Fix Download

PowerAI 1.6.1

|

Upgrade PowerAI 1.6.0 to WMLC 1.6.1 also known as PowerAI 1.6.1. To upgrade, refer to Upgrading PowerAI 1.6.0 to WMLC 1.6.1

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm poweraieq1.6.0