Boletines de Vulnerabilidades

IBM Security Bulletin: Security Vulnerability in Apache Batik (CVE-2015-0250)


Información sobre el sistema

   
Software afectado IBM

Descripción

Apache Batik could allow a remote attacker to obtain sensitive information. By persuading a victim to open a specially-crafted SVG file, an attacker could exploit this vulnerability to reveal files and obtain sensitive information. CVE(s): CVE-2015-0250 Affected product(s) and affected version(s): Rational Application Developer 9.1.1 and earlier Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_security_vulnerability_in_apache_batik_cve_2015_0250?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0250 ,CVE-2015-2613 ,CVE-2015-2601 ,CVE-2015-2625 ,CVE-2015-1931 ,CVE-2015-4749 ,CVE-2015-0488 ,CVE-2015-0478 ,CVE-2015-2808 ,CVE-2015-1916 ,CVE-2015-0204 ,CVE-2015-0286 ,CVE-2015-0288 ,CVE-2015-0289 and CVE-2015-0293.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT