IBM Support

Security Bulletin: A security vulnerability has been identified in Apache PDFBox which affects DataQuant

Created by Rita Zimmer on
Published URL:
https://www.ibm.com/support/pages/node/881952
881952

Security Bulletin


Summary

A security vulnerability has been identified in Apache PDFBox that could affect DataQuant for z/OS and DataQuant Multiplatforms.

Vulnerability Details

CVEID: 2018-11797
CVS Score: 5.5
Description: Apache PDFBox is vulnerable to a denial of service, caused by a flaw when parsing the page tree. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Affected Products and Versions

Principal Product
DataQuant for z/OS v2.1
DataQuant for Multiplatforms v2.1

Remediation/Fixes

  1. Close DataQuant.
  2. Download JRE (ibm-java-jre-80-win-i386) and extract the files to a temporary location.
  3. Replace jre folder at the install directory location –> “C:\Program Files (x86)\IBM\IBM DataQuant\DataQuant for Workstation”. Replace with contents in step # 2.
  4. Download eclipse oxygen from https://www.eclipse.org/downloads/download.php?file=/technology/epp/downloads/release/oxygen/3a/eclipse-jee-oxygen-3a-win32-x86_64.zip
  5. Extract the eclipse oxygen and copy the plugin - org.apache.jasper.glassfish_2.2.2.v201501141630.jar from eclipse-jee-oxygen-3a-win32-x86_64\eclipse\plugins
  6. Copy org.apache.jasper.glassfish_2.2.2.v201501141630.jar  in the folder where DataQuant is installed - C:\Program Files (x86)\IBM\IBM DataQuant\DataQuant for Workstation\plugins
  7. Delete the older plugin org.apache.jasper.glassfish_2.2.2.v201205150955.jar from the DataQuant install directory
  8. Delete the plugin pdfbox-1.7.0.jar present in the location where DataQuant in installed -> C:\Program Files (x86)\IBM\IBM DataQuant\DataQuant for Workstation\plugins\com.ibm.bi.thirdparty_2.1.7.20170216\Other
  9. Download the pdfbox plugin from https://pdfbox.apache.org/download.cgi. Copy the plugin pdfbox-1.8.16.jar to the folder where DataQuant is installed -> C:\Program Files (x86)\IBM\IBM DataQuant\DataQuant for Workstation\plugins\com.ibm.bi.thirdparty_2.1.7.20170216\Other
  10. Rename the jar from pdfbox-1.8.16.jar to pdfbox-1.7.0.jar

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSAUQR","label":"IBM DataQuant for z\/OS"},"Component":"","Platform":[{"code":"PF035","label":"z\/OS"}],"Version":"2.1","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
12 February 2021

UID

ibm10881952