Lucene search

K
ibmIBMEA8D82923E805035C7C050D5C567982BF7CF8C2914FBBBB13BA09E93C1480E2A
HistoryJan 14, 2022 - 11:51 p.m.

Security Bulletin: IBM FileNet Content Manager Operating System command injection security vulnerability

2022-01-1423:51:07
www.ibm.com
23

0.002 Low

EPSS

Percentile

56.6%

Summary

FileNet Content Manager component Administration Console for Content Platform Engine (ACCE) user Operating System command injection security vulnerability

Vulnerability Details

CVEID:CVE-2021-38965
**DESCRIPTION:**IBM FileNet Content Manager could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/212346 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
FileNet Content Manager 5.5.4
FileNet Content Manager 5.5.6
FileNet Content Manager 5.5.7

Remediation/Fixes

To resolve these vulnerabilities, install one of the patch sets listed below.

Product VRMF APAR Remediation/First Fix
FileNet Content Manager 5.5.4
5.5.6
5.5.7 PJ46654
PJ46654
PJ46654 5.5.4.0-P8CPE-IF007 - 1/14/2022
5.5.6.0-P8CPE-IF003 - 1/14/2022
5.5.7.0-P8CPE-IF002 - 1/14/2022

In the above table, the APAR links will provide more information about the fix.

Workarounds and Mitigations

None

0.002 Low

EPSS

Percentile

56.6%

Related for EA8D82923E805035C7C050D5C567982BF7CF8C2914FBBBB13BA09E93C1480E2A