Security Bulletin
Summary
Synthetic Playback Agent has addressed the following vulnerabilities: CVE-2020-26951, CVE-2020-16012, CVE-2020-26953, CVE-2020-26956, CVE-2020-26958, CVE-2020-26959, CVE-2020-26960, CVE-2020-15999, CVE-2020-26961, CVE-2020-26965, CVE-2020-26966, CVE-2020-26968
Vulnerability Details
CVEID: CVE-2020-26968
DESCRIPTION: Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by memory safety bugs within the browser engine. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191917 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2020-16012
DESCRIPTION: Google Chrome could allow a remote attacker to obtain sensitive information, caused by a side-channel information leakage in graphics. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191856 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVEID: CVE-2020-26951
DESCRIPTION: Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by a parsing and event loading mismatch in Firefox's SVG code. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to bypass security sanitizer for chrome privileged code.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191918 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVEID: CVE-2020-26953
DESCRIPTION: Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the ability to enter fullscreen mode without displaying the security UI. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to attempt a phishing attack or otherwise confuse the user.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191920 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVEID: CVE-2020-26966
DESCRIPTION: Mozilla Firefox could allow a remote attacker to obtain sensitive information, caused by the broadcasting of single-word queries to a local network. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191936 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVEID: CVE-2020-26956
DESCRIPTION: Mozilla Firefox is vulnerable to cross-site scripting, caused by improper validation of user-supplied input when removing HTML elements. A remote attacker could exploit this vulnerability using paste (manual and clipboard API) in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191923 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
CVEID: CVE-2020-26959
DESCRIPTION: Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in WebRequestService. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191926 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2020-26958
DESCRIPTION: Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the failure to block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause a cross-site script inclusion vulnerability or a Content Security Policy bypass.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191925 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVEID: CVE-2020-26965
DESCRIPTION: Mozilla Firefox could allow a remote attacker to obtain sensitive information, caused by the remembrance of typed passwords by software keyboards. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191935 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVEID: CVE-2020-26961
DESCRIPTION: Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the failure to filter IPv4 mapped IP Addresses by a DoH resolver. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to lead to a possible DNS rebinding attack.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191931 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
CVEID: CVE-2020-26960
DESCRIPTION: Mozilla Firefox could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in uses of nsTArray. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability using unknown attack vectors to execute arbitrary code on the vulnerable system or cause a denial of service.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191927 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Products and Versions
| Affected Product(s) | Version(s) |
| APM AM | 8.1.4 |
| BAM | 1.0 |
| APM SaaS | 8.1.4 |
| APM on-premise | 8.1.4 |
| ICAM | 2019.3.0 |
Remediation/Fixes
| Product Remediation | Fix |
| APM on-premise | Synthetic Playback Agent 8.1.4 IF13 |
| ICAM | ICAM 2020.2.3 |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
24 Nov 2020: Initial Publication
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
25 February 2021
UID
ibm16417173