IBM Security Bulletin: IBM FileNet Content Manager affected by Apache PDFBox security vulnerability

Share this post:

IBM FileNet Content Manager has addressed the following security vulnerability. Apache PDFBox is vulnerable to a denial of service, caused by an out of memory exception in AFMParser. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop. For more information please refer to the X-Force database entries referenced below.

CVE(s): CVE-2018-8036

Affected product(s) and affected version(s):

IBM FileNet Content Manager 5.2.1, 5.5.0, 5.5.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/docview.wss?uid=ibm10716315
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/145592



from IBM Product Security Incident Response Team https://ift.tt/2CA9g9H