Resource management error in Mesos - CVE-2018-11793
Published: March 6, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect processing of nested data within a JSON array. A remote unauthenticated attacker can supply a specially crafted JSON array, overflow the stack due to unbounded recursion and perform denial of service (DoS) attack,
Affected software
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2018-11793
Netcool Operations Insight - update to 1.6.8
IBM Cloud Pak for Watson AIOps - update to 3.7.1