Lucene search

K
ibmIBMF0CF06A35CFB9F883DE74CA58FDA5FB8E4CD4EED75B2FA4B80389117E7AAC99D
HistoryAug 06, 2018 - 4:33 p.m.

Security Bulletin: eDiscovery Manager is affected by public disclosed vulnerability from Apache Poi

2018-08-0616:33:54
www.ibm.com
14

0.014 Low

EPSS

Percentile

86.6%

Summary

Apache POI is vulnerable to a denial of service, caused by an error while parsing malicious WMF, EMF, MSG and macros and specially crafted DOC, PPT and XLS. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop or an out of memory exception.

Vulnerability Details

CVEID: CVE-2017-12626
DESCRIPTION: Apache POI is vulnerable to a denial of service, caused by an error while parsing malicious WMF, EMF, MSG and macros and specially crafted DOC, PPT and XLS. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop or an out of memory exception.
CVSS Base Score: 5.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/138361 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM eDiscovery Manager v2.2.2.3

Remediation/Fixes

Product

| VRM |Remediation
—|—|—
IBM eDiscovery Manager | 2.2.2.3 | Use IBM eDiscovery Manager 2.2.2.3 Interim Fix 001

Workarounds and Mitigations

None

CPENameOperatorVersion
ediscovery managereq2.2.2.3

0.014 Low

EPSS

Percentile

86.6%

Related for F0CF06A35CFB9F883DE74CA58FDA5FB8E4CD4EED75B2FA4B80389117E7AAC99D