SB2017091315 - Multiple vulnerabilities in IBM InfoSphere Information Server



SB2017091315 - Multiple vulnerabilities in IBM InfoSphere Information Server

Published: September 13, 2017

Security Bulletin ID SB2017091315
Severity
Low
Patch available
NO
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Privilege escalation (CVE-ID: CVE-2017-1467)

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The weakness exists due to weak authorization issue. A remote attacker can use man-in-the-middle techniques, replay certain DataStage commands without privileged access and gain
elevated privileges.

Successful exploitation of the vulnerability results in privilege escalation or unauthorized access to the system.

2) Untrusted search path (CVE-ID: CVE-2017-1468)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to untrusted search path element. A local attacker can place arbitrary .dll files in installation directories and execute arbitrary code with system privileges.

Successful exploitation of the vulnerability may result in system compromise.

3) XXE attack (CVE-ID: CVE-2017-1383)

The vulnerability allows a remote attacker to conduct XXE attack.

The weakness exists in the encryption library due to improper handling of XML External Entity (XXE) entries when parsing an XML file. A remote attacker can send manipulated XML data and gain access to arbitrary data or consume memory resources.

Successful exploitation of the vulnerability results in information disclosure.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.