Lucene search

K
ibmIBM17AD7BAA4B4B92B376991EA6E2FDE807376B44743890E9D9B34CC80855CC7FB1
HistoryDec 17, 2019 - 10:56 p.m.

Security Bulletin: Vulnerability in Apache Commons FileUpload affects IBM Sterling Secure Proxy (CVE-2016-3092)

2019-12-1722:56:50
www.ibm.com
32

0.043 Low

EPSS

Percentile

92.3%

Summary

An Apache Commons Collections vulnerability for handling Java object deserialization was addressed by IBM Sterling Secure Proxy.

Vulnerability Details

CVEID: CVE-2016-3092 DESCRIPTION: Apache Tomcat is vulnerable to a denial of service, caused by an error in the Apache Commons FileUpload component. By sending file upload requests, an attacker could exploit this vulnerability to cause the server to become unresponsive.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114336 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM Sterling Secure Proxy 3.4.2 through 3.4.3.0 iFix 1
IBM Sterling Secure Proxy 3.4.2 through 3.4.2.0 iFix 8

Remediation/Fixes

Product

| VRMF|APAR|How to acquire fix
—|—|—|—
IBM Sterling Secure Proxy| 3.4.3_.0_| iFix 2| Fix Central
IBM Sterling Secure Proxy| 3.4.2.0| iFix 9| Fix Central

Workarounds and Mitigations

None.