Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in legacy component distributed in IBM Development Package for Apache Spark (CVE-2012-5783)

   
Affected software IBM
 
The Jakarta Commons httpclient version 3.x is known to be vulnerable to SSL spoofing, and is included in the IBM Development Package for Apache Spark, primarily to provide legacy support for Hadoop 2.2. A patch is applied to Jakarta Commons httpclient version 3.1 to fix the vulnerability. Note: the IBM Development Package for Apache Spark version 1.x provides support for Hadoop 2.6, which does not exercise this vulnerability. The IBM Development Package for Apache Spark version 2.x provides

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerability-in-legacy-component-distributed-in-ibm-development-package-for-apache-spark-cve-2012-5783/