Lucene search

K
ibmIBME3D120D9BFE552F9F1D44942175EA984808C3EF087C47A2F389375EEFFDD831C
HistoryJan 28, 2020 - 3:09 p.m.

Security Bulletin: Multiple security vulnerabilities were fixed in IBM Security Access Manager Appliance (CVE-2019-3861, CVE-019-3858)

2020-01-2815:09:56
www.ibm.com
10

0.033 Low

EPSS

Percentile

91.4%

Summary

Multiple vulnerabilities were fixed in the libssh2 component used by the IBM Security Access Manager Appliance.

Vulnerability Details

CVEID:CVE-2019-3861
**DESCRIPTION:**An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
CVSS Base score: 5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/158345 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-3858
**DESCRIPTION:**An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
CVSS Base score: 5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/158342 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
ISAM 9.0

Remediation/Fixes

Affected Products Affected Releases APAR Fix Availability
IBM Security Access Manager Appliance 9.0.7 IJ21679 9.0.7-ISS-ISAM-FP0001

Workarounds and Mitigations

None