Lucene search

K
ibmIBMDB29BCE4476074FB279EB81B347B92F85A0F9384DFE344FAB177E69B9522392E
HistoryJan 29, 2024 - 7:20 p.m.

Security Bulletin: Content Manager Enterprise Edition and use of Oracle Outside In Technology Security Vulnerability (CVE-2013-5791, CVE-2013-5763)

2024-01-2919:20:06
www.ibm.com
16
vulnerability
oracle outside in
content manager enterprise edition
cve-2013-5791
cve-2013-5763
buffer overflow
security patch
version 8.4.3
version 8.5
upgrade

CVSS2

1.5

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.284

Percentile

96.9%

Summary

Oracle Outside In Technology has Security vulnerabilities which may be exposed within the use of Content Manager Enterprise Edition

Vulnerability Details

CVEID:CVE-2013-5791__ __ **DESCRIPTION: **
Content Manager Enterprise Edition bundles some of the tools provided by Oracle Outside In Technology. The Oracle Outside In Microsoft Access 1.x database file parser is vulnerable to a stack-based buffer overflow.

CVSS Base Score: 10
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/87925
for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVEID:CVE-2013-5763
DESCRIPTION:
Content Manager Enterprise Edition bundles some of the tools provided by Oracle Outside In Technology. Oracle Outside In Technology has additional security vulnerabilities which are fixed within the patch referred to below.

CVSS Base Score: 6.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/88557 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector:(AV:N/AC:M/Au:N/C:P/I:P/A:P)

Affected Products and Versions

CM 8.4.3 CM 8.5

Remediation/Fixes

<Product

| VRMF | APAR | Remediation/First Fix
β€”|β€”|β€”|β€”
Content Manager Enterprise Edition | 8.4.3
8.5 | | Upgrade to V8.4.3 FP4 or Higher
Upgrade to V8.5. FP1 or Higher

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcontent_managerMatch8.5enterprise
OR
ibmcontent_managerMatch8.4.3enterprise
VendorProductVersionCPE
ibmcontent_manager8.5cpe:2.3:a:ibm:content_manager:8.5:*:*:*:*:enterprise:*:*
ibmcontent_manager8.4.3cpe:2.3:a:ibm:content_manager:8.4.3:*:*:*:*:enterprise:*:*

CVSS2

1.5

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.284

Percentile

96.9%