Lucene search

K
ibmIBM1EC25119E647924C94723F6231A10DD39812C5612E120E454A71F2A733C3394C
HistoryJun 16, 2018 - 9:17 p.m.

Security Bulletin: Denial of Service with WebSphere Application Server affecting IBM Tivoli Security Policy Manager. (CVE-2014-0964)

2018-06-1621:17:47
www.ibm.com
10

EPSS

0.018

Percentile

88.3%

Summary

There is a potential denial of service with WebSphere Application Server versions 6.0.2 and 6.1. These affected versions of WebSphere Application Server are supported for use with IBM Tivoli Security Policy Manager.

Vulnerability Details

CVEID: _
CVE-2014-0964_

DESCRIPTION:

There is a potential denial of service in IBM WebSphere Application Server versions 6.0.2 and 6.1. If you run a Heartbleed scanning tool or send specially crafted Heartbeat messages to the server, it can cause the IBM SDK for Java for WebSphere Application Server to become stuck in a processing loop resulting in high CPU usage. If enough processing loops are generated, the server may become unresponsive and require a server restart. There is no impact to confidentiality or integrity.

CVSS Base Score: 7.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/92877 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C)

Affected Products and Versions

    • IBM Tivoli Security Policy Manager (TSPM) versions 7.0 and 7.1

Please check your WebSphere version to determine if you are using one of the affected versions.

Remediation/Fixes

If you are running one of the affected WebSphere versions listed in the Affected Products section above, update your IBM WebSphere Application Server with the appropriate Interim Fix based on information in the WebSphere security bulletin link below.

Product Remediation/First Fix
TSPM 7.0, 7.1 PI16981 _(For __WebSphere _6.1.0.0 through 6.1.0.47)

Workarounds and Mitigations

If customers are using Heartbleed tools to detect the OpenSSL Heartbleed vulnerability they should stop using the tool.

EPSS

0.018

Percentile

88.3%

Related for 1EC25119E647924C94723F6231A10DD39812C5612E120E454A71F2A733C3394C