Lucene search

K
ibmIBM32EB8BE682985EED6CDB1D2FE6AAA4C3E1F475A6C6763236F416CF5D1908DDD8
HistoryJun 15, 2018 - 7:06 a.m.

Security Bulletin: A security vulnerability has been identified in Apache Commons shipped with IBM Support Assistant Team Server (CVE-2016-3092)

2018-06-1507:06:04
www.ibm.com
15

0.043 Low

EPSS

Percentile

92.3%

Summary

Apache Commons is shipped with IBM Support Assistant Team Server. Information about a security vulnerability affecting Apache Commons has been published in a security bulletin.

Vulnerability Details

CVEID: CVE-2016-3092** **
DESCRIPTION: Apache Tomcat is vulnerable to a denial of service, caused by an error in the Apache Commons FileUpload component. By sending file upload requests, an attacker could exploit this vulnerability to cause the server to become unresponsive.

CVSS Base Score: 5.3 **CVSS Temporal Score:**See <https://exchange.xforce.ibmcloud.com/vulnerabilities/114336&gt; for the current score *CVSS Environmental Score:**Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM Support Assistant Team Server: 5.0.0 - 5.0.2.2

Remediation/Fixes

The recommended solution is to install the new IBM Support Assistant Team Server 5.0.2.3: http://www-01.ibm.com/software/support/isa/teamserver.html

Workarounds and Mitigations

None