Denial of service in IBM iNotes - CVE-2017-7957

 

Denial of service in IBM iNotes - CVE-2017-7957

Published: October 4, 2017 / Updated: October 11, 2017


Vulnerability identifier: #VU8802
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7957
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to XStream mishandles attempts to create an instance of the primitive type 'void' during unmarshalling when a certain denyTypes workaround is not used. A remote attacker can perform demonstrated by an xstream.fromXML("<void/>") call, trigger an unmarshalling error in XStream and cause the target service to crash.

Successful exploitation of the vulnerability results in denial of service.


Affected software

IBM iNotes
Debian Linux
Bamboo Server
IBM Watson Discovery for IBM Cloud Pak for Data
Storage Copy Data Management

How to mitigate CVE-2017-7957

Install update from vendor's website.

Bamboo Server - update to 9.2.8
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0

External References

Related Security Bulletins