QID 376208

Date Published: 2022-01-05

QID 376208: IBM Sterling Connect Direct File Agent FasterXML Vulnerability in Jackson-Databind (6474939)

There is a vulnerability in FasterXML jackson-databind used by IBM Sterling Connect:Direct File Agent. IBM Sterling Connect:Direct File Agent has addressed the applicable CVE-2018-7489.

Affected Versions:
Sterling Connect Direct File Agent 1.4.0.0 - 1.4.0.2_iFix007

FasterXML jackson-databind could allow a remote attacker to execute arbitrary code on the system, caused by a deserialization flaw in the readValue method of the ObjectMapper. By sending specially crafted JSON input, an attacker could exploit this vulnerability to execute arbitrary code on the system

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to IBM Sterling Connect Direct File Agent 1.4.0.2_iFix008 or later
    Vendor References

    CVEs related to QID 376208

    Software Advisories
    Advisory ID Software Component Link
    6474939 URL Logo www.ibm.com/support/pages/node/6474939