IBM Security Bulletin: IBM FileNet Content Manager affected by Apache PDFBox security vulnerability
Oct 10, 2018 9:00 am EDT
Categorized: Medium Severity
Share this post:
IBM FileNet Content Manager has addressed the following security vulnerability. Apache PDFBox is vulnerable to a denial of service, caused by an out of memory exception in AFMParser. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop. For more information please refer to the X-Force database entries referenced below.
CVE(s): CVE-2018-8036
Affected product(s) and affected version(s):
IBM FileNet Content Manager 5.2.1, 5.5.0, 5.5.1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/docview.wss?uid=ibm10716315
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/145592
from IBM Product Security Incident Response Team https://ift.tt/2CA9g9H