Information disclosure in PCRE - CVE-2015-8393

 

Information disclosure in PCRE - CVE-2015-8393

Published: March 28, 2024


Vulnerability identifier: #VU87881
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8393
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to pcregrep in PCRE mishandles the -q option for binary files. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

PCRE
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Intelligent Operations Center
WebSphere Remote Server
IBM Security Verify Governance
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
Storage Protect Server
Fedora
IBM Cloud Pak System
pcre
IBM DB2 LUW

How to mitigate CVE-2015-8393

Install updates from vendor's website.

PCRE - update to 8.38
Db2 Big SQL - update to 7.6.2
dashDB Local - update to 11.5.9.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
pcre - update to 8.38-1.fc22
IBM DB2 LUW - addressed in versions 10.5 FP11, 11.1.4 FP7, 11.5.0, 11.5.8

External References

Related Security Bulletins