Lucene search

K
ibmIBME455072BD221DBB8B1C58AAE10839300D4B2DB2A7147F02EDADB4E2016749D64
HistoryDec 17, 2019 - 5:30 p.m.

Security Bulletin: IBM API Connect is impacted by a vulnerability in libexpat (CVE-2019-15903)

2019-12-1717:30:16
www.ibm.com
40

0.005 Low

EPSS

Percentile

76.5%

Summary

IBM API Connect has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-15903
**DESCRIPTION:**In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/166560 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM API Connect 2018.1-2018.4.1.7

Remediation/Fixes

Affected releases Fixed in VRMF APAR Remediation / First Fix
IBM API Connect V2018.1-2018.4.1.7

v2018.4.1.8

|

LI81254

|

Addressed in IBM API Connect v2018.4.1.8.

All components are impacted.

Follow this link and find the OVA package appropriate

form factor for your installation.

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+

Connect&release=2018.4.1.7&platform=All&function=all&source=fc

Workarounds and Mitigations

None