Vulnerability in Tika's SQLite3Parser - BloomReach Experience - Open Source CMS

Vulnerability in Tika's SQLite3Parser 

Issue date: 29-04-2019
Affects versions: 13.0, 12.6, 11.2

Issue ID: SECURITY-99

Affected Product Version(s)

This vulnerability affects all versions of both CMS and delivery applications based on Bloomreach Experience Manager prior to 11.2.12, 12.6.2, and 13.0.1, and earlier versions.


Severity 

Medium


Description

CVE-2018-17197  

A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.

 

Instructions

Every customer is strongly advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.