Lucene search

K
ibmIBM12C657CCB040A2D71F5E7B37692A10A6A4BAA07FBFEAADA8E6F9A5BCFCFD9FAB
HistoryJun 15, 2018 - 7:08 a.m.

Security Bulletin: Security Vulnerabilities in IBM HTTP Server (CVE-2017-9798, CVE-2017-12618)

2018-06-1507:08:17
www.ibm.com
35

0.974 High

EPSS

Percentile

99.9%

Summary

There is an information disclosure vulnerability and a denial of service vulnerability that affect the IBM HTTP Server used by WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2017-9798**
DESCRIPTION:** Apache HTTP Server could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/132159 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID: CVE-2017-12618**
DESCRIPTION:** Apache Portable Runtime Utility (APR-util)is vulnerable to a denial of service, caused by failing to validate the integrity of SDBM database files used by apr_sdbm*() functions. By making a specially-crafted program or process, a local authenticated attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 5.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/134048 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

These vulnerabilities affect the following versions and releases of IBM HTTP Server (powered by Apache) component in all editions of WebSphere Application Server and bundling products.

  • Version 9.0
  • Version 8.5
  • Version 8.0
  • Version 7.0

Remediation/Fixes

The fixes for these are both of these vulnerabilities are contained in interim fix PI87445.

PI87445 - CVE-2017-9798 for IBM HTTP Server
PI87663 - CVE-2017-12618 for IBM HTTP Server

For V9.0.0.0 through 9.0.0.5:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PI87445

--OR–
· Apply Fix Pack 9.0.0.6 or later.

**
For V8.5.0.0 through 8.5.5.12:**

· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PI87445

--OR–
· Apply Fix Pack 8.5.5.13 or later.
**

For V8.0.0.0 through 8.0.0.14:**
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PI87445

--OR–
· Apply Fix Pack 8.0.0.15 or later.

**
For V7.0.0.0 through 7.0.0.43:**
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PI87445

--OR–
· Apply Fix Pack 7.0.0.45 or later.

Workarounds and Mitigations

none