Friday, March 30, 2018

IBM Security Bulletin: IBM Web Experience Factory is Affected by an Apache Poi Vulnerability

Share this post:

IBM Web Experience Factory has addressed the following vulnerability. Apache POI is vulnerable to a denial of service, caused by an error while parsing malicious WMF, EMF, MSG and macros and specially crafted DOC, PPT and XLS.

CVE(s): CVE-2017-12626

Affected product(s) and affected version(s):

IBM Web Experience Factory 8.0
IBM Web Experience Factory 8.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22014912
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/138361



from IBM Product Security Incident Response Team https://ift.tt/2GmBHpZ

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.