Out-of-bounds read in bl - CVE-2020-8244

 

Out-of-bounds read in bl - CVE-2020-8244

Published: May 15, 2023


Vulnerability identifier: #VU76124
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-8244
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote attacker can create a specially crafted file and trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

bl
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Db2 Graph
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Automation Manager
Netcool Operations Insight
Data Replication on Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Edge Application Manager
Ubuntu
node-bl (Ubuntu package)

How to mitigate CVE-2020-8244

Install updates from vendor's website.

bl - addressed in versions 1.2.3, 2.2.1, 3.0.1, 4.0.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
node-bl (Ubuntu package) - update to 1.1.2-1ubuntu1.1
Netcool Operations Insight - update to 1.6.11
Data Replication on Cloud Pak for Data - update to 4.6.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3

External References

Related Security Bulletins