Tuesday, February 4, 2020

Security Bulletin: A vulneraqbility in SQLite affects IBM Cloud Application Performance Managment R esponse Time Monitoring Agent (CVE-2019-16168)

SQLite is vulnerable to a denial of service, caused by missing validation of a sqlite_stat1 sz field in whereLoopAddBtreeIndex in sqlite3.c. By providing specially-crafted input, a remote attacker could exploit this vulnerability to cause the application to crash.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Performance Management – Response Time Monitoring Agent 8.1.3
IBM Cloud Application Performance Management – Response Time Monitoring Agent 8.1.4
IBM Tivoli Composite Application Manager for Transactions (Response Time) 7.4.0.1
IBM Tivoli Composite Application Manager for Transactions (Response Time) 7.4.0.2

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1274422

The post Security Bulletin: A vulneraqbility in SQLite affects IBM Cloud Application Performance Managment R esponse Time Monitoring Agent (CVE-2019-16168) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2GX0EtW

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.