Medium Severity

IBM Security Bulletin: IBM Notes Open Source Expat Vulnerabilities disclsoure

Share this post:

IBM Notes consumes Expat XML Parser for which the vulnerabilities are reported. Expat XML Parser is used by Keyview 10.22 library which is consumed by IBM Notes. IBM will address this vulnerability by updating fixes provided by HP to the existing Keyview 10.22 library.

CVE(s): CVE-2012-6702, CVE-2016-5300

Affected product(s) and affected version(s):

IBM Notes 9.0.1 to 9.0.1 FP7
IBM Notes 9.0 to 9.0 IF4
IBM Notes 8.5.3 to 8.5.3 FP6 IF13
IBM Notes 8.5.2 to 8.5.2 FP4 IF3
IBM Notes 8.5.1. to 8.5.1 FP5 IF3
IBM Notes 8.5 release

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21990658
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/114541
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/114435

More stories

IBM Security Bulletin: IBM Security Key Lifecycle Manager stores password in clear text (CVE-2019-4566)

Sep 21, 2019 9:02 am EDT | Medium Severity

IBM Security Key Lifecycle Manager stores user credentials in plain in clear text which can be read by a local user. CVE(s): CVE-2019-4566 Affected product(s) and affected version(s): IBM Security Key Lifecycle Manager (SKLM) v3.0 – v3.0.0.2 on distributed platforms IBM Security Key Lifecycle Manager (SKLM) v3.0.1- v3.0.1.1 on distributed platforms Refer to the following ...read more


IBM Security Bulletin: Apache Commons Compress vulnerability affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-12402)

Sep 21, 2019 9:02 am EDT | Medium Severity

Apache Commons Compress is vulnerable to a denial of service which can affect IBM Spectrum Control (formerly IBM Tivoli Storage Productivity Center). CVE(s): CVE-2019-12402 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Tivoli Storage Productivity Center 5.2.0 – 5.2.7.1 IBM Spectrum Control 5.2.8 – 5.2.17.3 IBM Spectrum Control 5.3.0 – 5.3.3 The versions ...read more


IBM Security Bulletin: Clickjacking vulnerability in WebSphere Application Server Liberty affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-4285)

Sep 21, 2019 9:01 am EDT | Medium Severity

There is a potential clickjacking vulnerability in IBM WebSphere Application Server Liberty Admin Center which affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center). CVE(s): CVE-2019-4285 Affected product(s) and affected version(s): Affected Product Affected Versions IBM Spectrum Control 5.2.13 – 5.2.17.3 IBM Spectrum Control 5.3.0 – 5.3.3 The versions listed above apply to all licensed ...read more