Denial of service in IBM iNotes - CVE-2017-7957
Published: October 4, 2017 / Updated: October 11, 2017
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to XStream mishandles attempts to create an instance of the primitive type 'void' during unmarshalling when a certain denyTypes workaround is not used. A remote attacker can perform demonstrated by an xstream.fromXML("<void/>") call, trigger an unmarshalling error in XStream and cause the target service to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Debian Linux
Bamboo Server
IBM Watson Discovery for IBM Cloud Pak for Data
Storage Copy Data Management
How to mitigate CVE-2017-7957
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0