QID 376208
Date Published: 2022-01-05
QID 376208: IBM Sterling Connect Direct File Agent FasterXML Vulnerability in Jackson-Databind (6474939)
There is a vulnerability in FasterXML jackson-databind used by IBM Sterling Connect:Direct File Agent. IBM Sterling Connect:Direct File Agent has addressed the applicable CVE-2018-7489.
Affected Versions:
Sterling Connect Direct File Agent 1.4.0.0 - 1.4.0.2_iFix007
FasterXML jackson-databind could allow a remote attacker to execute arbitrary code on the system, caused by a deserialization flaw in the readValue method of the ObjectMapper. By sending specially crafted JSON input, an attacker could exploit this vulnerability to execute arbitrary code on the system
Solution
Vendor has released fix to address these vulnerabilities. Refer to IBM Sterling Connect Direct File Agent 1.4.0.2_iFix008 or later
Vendor References
- IBM Sterling Connect -
www.ibm.com/support/pages/node/6474939
CVEs related to QID 376208
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6474939 |
|