Friday, March 8, 2019

IBM Security Bulletin: FileNet CMIS (FNCMIS) leveraging Spring Framework is vulnerable to a denial of service caused by improper handling of range request by the ResourceHttpRequestHandler

FileNet Content Management Interoperability Services (CMIS), which ships with IBM Content Navigator, is affected by the following vulnerability: Spring Framework’s improper handling of ResourceHttpRequestHandler could result in denial of service condition.

CVE(s): CVE-2018-15756

Affected product(s) and affected version(s):
IBM ECM CMIS and FileNet Collaboration Services 3.0.4

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10872210
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/151641

The post IBM Security Bulletin: FileNet CMIS (FNCMIS) leveraging Spring Framework is vulnerable to a denial of service caused by improper handling of range request by the ResourceHttpRequestHandler appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2IXovh2

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.