Lucene search

K
ibmIBMFD584733E27E9924DE4A2C7FC8599297DB665C0E65024B3729BE4697563E467B
HistoryDec 09, 2020 - 4:41 a.m.

Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in PostgreSQL

2020-12-0904:41:58
www.ibm.com
19
ibm watson discovery
ibm cloud pak for data
postgresql
vulnerability
cve-2020-14349
cve-2020-14350
remote attacker
arbitrary command
system
sql command
replication
installation
upgrade

EPSS

0.002

Percentile

60.6%

Summary

IBM Watson Discovery for IBM Cloud Pak for Data contains a vulnerable version of PostgreSQL.

Vulnerability Details

CVEID:CVE-2020-14349
**DESCRIPTION:**PostgreSQL could allow a remote authenticated attacker to execute arbitrary command on the system, caused by improper sanitization of search_path during logical replication. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary SQL command in the context of the user used for replication.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187185 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2020-14350
**DESCRIPTION:**PostgreSQL could allow a remote authenticated attacker to execute arbitrary code on the system, caused by the failure to use search_path safely in their installation script. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary script.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187183 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ICP - Discovery 2.0.0-2.1.4

Remediation/Fixes

Upgrade to IBM Watson Discovery 2.2.0

<https://cloud.ibm.com/docs/discovery-data?topic=discovery-data-install&gt;

Workarounds and Mitigations

None