Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in dependent component distributed in IBM Development Package for Apache Spark (CVE-2015-1832)

   
Affected software IBM
 
Apache Derby versions up to 10.12.1.1 may be susceptible to an XML external entity (XXE) attack. Hive’s metastore, where created, requires Derby when Apache Hadoop data sources are used with Apache Spark. Apache Derby is therefore included in the IBM Development Package for Apache Spark.CVE(s): CVE-2015-1832Affected product(s) and affected version(s):IBM Development Package for Apache Spark 1.6.2.0 and earlier releases.Refer to the following reference URLs for remediation and additional

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerability-in-dependent-component-distributed-in-ibm-development-package-for-apache-spark-cve-2015-1832/