Lucene search

K
ibmIBMEB2C0B178C0F7DED96771723AB19B88E839004652E69528DB9271DCE88DE714E
HistoryApr 20, 2021 - 6:10 a.m.

Security Bulletin: protobuf Vulnerability in Apache Solr affect IBM Operations Analytics - Log Analysis Analysis (CVE-2015-5237)

2021-04-2006:10:31
www.ibm.com
14

0.017 Low

EPSS

Percentile

87.8%

Summary

A potential Buffer Error and Out-of-Bounds Write vulnerabilities in protobuf were addressed by IBM Operations Analytics - Log Analysis.

Vulnerability Details

CVEID:CVE-2015-5237
**DESCRIPTION:**Google Protocol Buffers could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in MessageLite::SerializeToString. A remote attacker could exploit this vulnerability to execute arbitrary code on the vulnerable system or cause a denial of service.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/105989 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
Log Analysis 1.3.1
Log Analysis 1.3.2
Log Analysis 1.3.3
Log Analysis 1.3.4
Log Analysis 1.3.5
Log Analysis 1.3.6

Remediation/Fixes

Principal Product and Version(s) : Fix details
IBM Operations Analytics - Log Analysis version 1.3.x Upgrade to Log Analysis version 1.3.7
Download the 1.3.7-TIV-IOALA-FP here

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm smartcloud analyticseq1.3.

0.017 Low

EPSS

Percentile

87.8%

Related for EB2C0B178C0F7DED96771723AB19B88E839004652E69528DB9271DCE88DE714E