Jul 5, 2019 9:00 am EDT
Categorized: High Severity
Share this post:
IBM Cúram Social Program Management uses the Google Guava library indirectly through Google Guice. In versions of Google Guava library before version 24.1.1, an unbounded memory allocation vulnerability enables remote attackers to conduct denial of service attacks against servers that depend on the library, and to deserialize attacker-provided data.
CVE(s): CVE-2018-10237
Affected product(s) and affected version(s):
IBM Cúram Social Program Management 7.0.5.0 – 7.0.6.0 IBM Cúram Social Program Management 7.0.0.0 – 7.0.4.0
Note: The Google Guava library was not present in version 6.1.x and earlier versions, so these versions are not vulnerable.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10886175
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/142508
from IBM Product Security Incident Response Team https://ift.tt/2YIhMLa
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.