Thursday, April 5, 2018

IBM Security Bulletin: Information Disclosure in IBM HTTP Server and Denial of Service in Apache CXF used by IBM WebSphere Application Server for IBM Cloud (CVE-2017-12613, CVE-2017-12624)

Share this post:

There is a potential information disclosure in IBM HTTP Server used by WebSphere Application Server. There is a potential denial of service in Apache CXF that is used by WebSphere Application Server.

CVE(s): CVE-2017-12613, CVE-2017-12624

Affected product(s) and affected version(s):

This vulnerability affects the following versions and releases of IBM HTTP Server (powered by Apache) component in all editions of WebSphere Application Server and bundling products.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22015297
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134049
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/135095



from IBM Product Security Incident Response Team https://ift.tt/2GWO0Nj

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.