IBM Security Bulletin: Vulnerabilities in Apache Spark affect IBM Operations Analytics Predictive Insights (CVE-2018-8024, CVE-2018-1334)
Nov 8, 2018 8:01 am EST
Categorized: High Severity
Share this post:
Apache Spark is used by IBM Operations Analytics Predictive Insights. IBM Operations Analytics Predictive Insights has addressed the applicable CVEs. Note that the usage of Apache Spark within IBM Operations Analytics Predictive Insights is limited to the REST Mediation utility. If you do not use that utility then you are not affected by this bulletin.
CVE(s): CVE-2018-8024, CVE-2018-1334
Affected product(s) and affected version(s):
IBM Operations Analytics Predictive Insights v1.3.6
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10738357
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146304
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146303
from IBM Product Security Incident Response Team https://ift.tt/2OyU0LN