Lucene search

K
ibmIBMFA424216868AEEEED93C29B1CA41D148223A111BBB5952CF1E5BFAD57FCC9D5D
HistoryJul 23, 2021 - 6:03 p.m.

Security Bulletin: Apache Commons Configuration Vulnerability Affects IBM Sterling Connect:Direct File Agent (CVE-2020-1953)

2021-07-2318:03:14
www.ibm.com
9

0.006 Low

EPSS

Percentile

79.2%

Summary

There is a vulnerability in Apache Commons used by IBM Sterling Connect:Direct File Agent. IBM Sterling Connect:Direct File Agent has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2020-1953
**DESCRIPTION:**Apache Commons Configuration could allow a remote attacker to execute arbitrary code on the system, caused by an issue when allowing the instantiation of classes (including special statements) by default. By persuading a victim to load a specially-crafted YAML file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177759 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Sterling Connect Direct File Agent 1.4.0.0 - 1.4.0.2_iFix007

Remediation/Fixes

Affected Product(s) Version(s) APAR Remediation / First Fix
Sterling Connect Direct File Agent 1.4 IT37680 Apply 1.4.0.2_iFix008 or later, available on Fix Central
For unsupported versions IBM recommends upgrading to a fixed, supported version of the product.

Workarounds and Mitigations

None

0.006 Low

EPSS

Percentile

79.2%

Related for FA424216868AEEEED93C29B1CA41D148223A111BBB5952CF1E5BFAD57FCC9D5D