IBM WebSphere Cast Iron Solution & App Connect Professional has addressed the following vulnerabilities reported in Apache Tomcat.
CVEID:CVE-2019-0221
**DESCRIPTION:**The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/161746 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
WebSphere Cast Iron v 7.5.0.0, 7.5.0.1, 7.5.1.0
WebSphere Cast Iron v 7.0.0.0, 7.0.0.1, 7.0.0.2
App Connect Professional v 7.5.2.0
App Connect Professional v 7.5.3.0
Product | VRMF | APAR | Remediation/First Fix |
---|---|---|---|
IBM Cast Iron | 7.0.0.0 | ||
7.0.0.1 | |||
7.0.0.2 | LI80954 | 7002 Fixcentral Link | |
IBM Cast Iron | 7.5.0.0 | ||
7.5.0.1 | |||
7.5.1.0 | LI80954 | 7510 fixcentral Link | |
App Connect Professional | 7.5.2.0 | LI80954 | 7520 Fixcentral link |
App Connect Professional | 7.5.3.0 | LI80954 | 7530 Fixcentral link |
None