Improper input validation in MySQL Cluster - CVE-2020-5258

 

Improper input validation in MySQL Cluster - CVE-2020-5258

Published: July 16, 2020


Vulnerability identifier: #VU30113
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5258
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Cluster: Packaging (dojo) component in MySQL Cluster. A remote authenticated user can exploit this vulnerability to gain access to sensitive information.


Affected software

MySQL Cluster
IBM Tivoli Monitoring
IBM Cloud Transformation Advisor
Oracle Communications Application Session Controller
IBM Elastic Storage System
IBM Cloud Pak for Business Automation
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Sterling B2B Integrator
IBM Common Licensing
IBM Security Verify Governance
IBM Cloud Orchestrator
IBM WebSphere Application Server
Oracle WebLogic Server
Oracle Communications Pricing Design Center
Oracle WebCenter Sites
Oracle Application Testing Suite
Financial Transaction Manager for High Value Payments
Primavera Unifier
IBM Spectrum Scale
Jazz Foundation

How to mitigate CVE-2020-5258

Install updates from vendor's website.

IBM Elastic Storage System - addressed in versions 6.0.2.2, 6.1.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.10
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.10
Financial Transaction Manager for High Value Payments - update to 3.2.11
IBM Spectrum Scale - addressed in versions 5.0.5.8, 5.1.1.2
IBM Spectrum Scale for IBM Elastic Storage Server - update to 5.3.7.2
IBM Sterling B2B Integrator - update to 6.1.2.2
Jazz Foundation - addressed in versions 7.0.2.0.29, 7.0.3.0.8
IBM Common Licensing - update to 9.0.0.1
IBM Security Verify Governance - update to 10.0.2

External References

Related Security Bulletins