Security Bulletin
Summary
IBM BladeCenter Advanced Management Module (AMM) has addressed the following vulnerabilities in libxml2.
Vulnerability Details
CVEID: CVE-2018-14404
DESCRIPTION: A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/147260 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
CVEID: CVE-2016-9318
DESCRIPTION: libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/119018 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Affected Products and Versions
Product(s) |
Version |
IBM BladeCenter Advanced Management Module (AMM) |
bpet |
IBM BladeCenter T Advanced Management Module (AMM) |
bbet |
Remediation/Fixes
Firmware fix versions are available on Fix Central: http://www.ibm.com/support/fixcentral/
Product(s) |
Fixed Version |
IBM BladeCenter Advanced Management Module (AMM) |
bpet68m-3.68m |
IBM BladeCenter T Advanced Management Module (AMM) |
bbet68m-3.68m |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
09 Jan 2020: Initial Publication
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
More support for:
System x Blades
Software version:
All
Operating system(s):
Firmware
Document number:
1170442
Modified date:
09 January 2020
UID
ibm11170442