IBM Support

Security Bulletin: Vulnerability in Apache Xerces-C XML parser, including XML4C affects IBM InfoSphere Optim Data Growth & Test Data Management & Application Retirement

Created by Richard Spagna on
Published URL:
https://www.ibm.com/support/pages/node/554343
554343

Security Bulletin


Summary

Open Source Xerces-C XML parser vulnerability affects IBM InfoSphere Optim Data Growth & Test Data Management & Application Retirement, also known as the server components.

Vulnerability Details

CVEID: CVE-2016-0729
DESCRIPTION: Apache Xerces-C XML Parser library is vulnerable to a denial of service, caused by improper bounds checking during processing and error reporting. By sending specially crafted input documents, an attacker could exploit this vulnerability to cause the library to crash or possibly execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111028 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affects IBM InfoSphere Optim solutions and editions versions 9.1 and 11.3 running on all supported platforms.

Both editions (Enterprise and Workgroup) of the following products are affected:

Optim Archive
Optim Data Privacy
Optim Test Data Management

All variations of the following solutions are affected:

Optim Data Growth Solution
Optim Solution for Application Retirement
Optim Test Data Management Solution

Remediation/Fixes

For the 11.3 release, fix pack 4 (11.3.0.4) and iFix 153 are required before installing iFix 215. That is, install 11.3.0.4, then iFix 153, then iFix 215.

For the 9.1 release, fix pack 6 (9.1.0.6) is required before installing iFix 208.

ProductVRMFiFixRemediation/First Fix
IBM InfoSphere Optim server components11.3215- Apply IBM InfoSphere Optim 11.3.0.4
- Apply IBM InfoSphere Optim iFix 153
- Apply IBM InfoSphere Optim iFix 215
IBM InfoSphere Optim solutions and editions9.1208- Apply IBM InfoSphere Optim 9.1.0.6
- Apply IBM InfoSphere Optim iFix 208

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

13 January 2017: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

PSIRT 5417, Record 88715

[{"Product":{"code":"SSMLQ4","label":"IBM InfoSphere Optim Test Data Management Solution"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"9.2;9.1;11.3.0","Edition":"Enterprise;Workgroup","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
08 July 2021

UID

swg21992210