Lucene search

K
ibmIBM208AFB43FBC2661BF413F32165110AB01864E60DF3DA14917109F64E61ED17F3
HistoryOct 03, 2018 - 9:40 p.m.

Security Bulletin: Vulnerabilities in apache2 affect IBM BladeCenter Advanced Management Module (AMM)

2018-10-0321:40:01
www.ibm.com
13

0.026 Low

EPSS

Percentile

90.4%

Summary

IBM BladeCenter Advanced Management Module (AMM) has addressed the following vulnerabilities in apache2.

Vulnerability Details

CVEID: CVE-2018-1312 DESCRIPTION: Apache HTTPD could allow a remote attacker to bypass security restrictions, caused by the failure to properly generate an HTTP Digest authentication nonce when generating an HTTP Digest authentication challenge. An attacker could exploit this vulnerability to replay HTTP requests across servers without detection.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/140853&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2018-1301 DESCRIPTION: Apache HTTPD is vulnerable to a denial of service, caused by an out-of-bounds access error after a header size limit has been reached reading the HTTP header. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to cause the service to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/140852&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2017-15710 DESCRIPTION: Apache HTTPD is vulnerable to a denial of service, caused by an out-of-bounds memory write error. By sending a specially crafted Accept-Language header value, an attacker could exploit this vulnerability to cause the service to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/140858&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Product

|

Affected Version

β€”|β€”

IBM BladeCenter Advanced Management Module (AMM)

|

BPET

Remediation/Fixes

Firmware fix versions are available on Fix Central: http://www.ibm.com/support/fixcentral/

Product

|

Fix Version

β€”|β€”

IBM BladeCenter Advanced Management Module (AMM)
(ibm_fw_amm_bpet68k-3.68k_anyos_noarch)

|

bpet68k-3.68k

Workarounds and Mitigations

None

CPENameOperatorVersion
system x bladeseqany