Friday, July 5, 2019

IBM Security Bulletin: Vulnerability in Google Guava affects IBM Cúram Social Program Management (CVE-2018-10237)

Jul 5, 2019 9:00 am EDT

Categorized: High Severity

Share this post:

IBM Cúram Social Program Management uses the Google Guava library indirectly through Google Guice. In versions of Google Guava library before version 24.1.1, an unbounded memory allocation vulnerability enables remote attackers to conduct denial of service attacks against servers that depend on the library, and to deserialize attacker-provided data.

CVE(s): CVE-2018-10237

Affected product(s) and affected version(s):
IBM Cúram Social Program Management 7.0.5.0 – 7.0.6.0 IBM Cúram Social Program Management 7.0.0.0 – 7.0.4.0
Note: The Google Guava library was not present in version 6.1.x and earlier versions, so these versions are not vulnerable.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10886175
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/142508



from IBM Product Security Incident Response Team https://ift.tt/2YIhMLa

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.