IBM Support

JR58835: SECURITY APAR - CVE-2017-7525 - REMOTE CODE EXECUTION OPEN SOURCE LIBRARY MIGHT AFFECT IBM BPM

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • A vulnerable version of the Jackson JSON library shipped with
    IBM Business Process Manager (BPM) V8.5.7 and IBM BPM V8.6
    2017.09.
    
    CVEID: CVE-2017-7525
    DESCRIPTION: A deserialization flaw within the Jackson JSON
    library in the readValue method of the ObjectMapper could allow
    a remote attacker to execute arbitrary code on the system. By
    sending a specially crafted request, an attacker could exploit
    this vulnerability to execute arbitrary code on the system.
    CVSS Base Score: 9.8
    CVSS Temporal Score:
    See https://exchange.xforce.ibmcloud.com/vulnerabilities/134639 
    for the current score
    CVSS Environmental Score*: Undefined
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix that updates the vulnerable library will be available for
    IBM BPM V8.5.7 cumulative fix (CF) 2017.06. The fix is also
    included in IBM BPM V8.6 CF2017.12.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR58835

  • Reported component name

    BPM

  • Reported component ID

    5737A5700

  • Reported release

    860

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-12-19

  • Closed date

    2018-02-09

  • Last modified date

    2018-02-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BPM

  • Fixed component ID

    5737A5700

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSFPJS","label":"IBM Business Process Manager"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.6.0.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
14 September 2022