Lucene search

K
ibmIBM332EB7C24BEDDB6A08EB1D2E56168DBF8FB7B8EE1E89939D477827DEB2BC62FA
HistoryJan 16, 2019 - 8:05 p.m.

Security Bulletin: IBM FileNet Content Manager affected by Apache HttpClient security vulnerability

2019-01-1620:05:01
www.ibm.com
39

0.002 Low

EPSS

Percentile

62.1%

Summary

Security vulnerability may affect Apache HttpClient used by IBM FileNet Content Manager.

Vulnerability Details

CVEID: CVE-2012-5783 DESCRIPTION: Apache Commons HttpClient could allow a remote attacker to conduct spoofing attacks, caused by the failure to verify that the server hostname matches a domain name in the subject’s Common Name (CN) field of the X.509 certificate. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/79984&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

IBM Content Manager 5.2.1, 5.5.0, 5.5.1

Remediation/Fixes

To resolve these vulnerabilities, install one of the releases below.

Product VRMF APAR Remediation/First Fix
FileNet Content Manager

5.2.1
5.5.0
5.5.1

|

PJ45429
PJ45429
PJ45429

| 5.2.1.7-P8CPE-IF004 - 10/8/2018
5.5.0.0-P8CPE-IF003 - 12/14/2018
5.5.1.0-P8CPE-IF002 - 1/15/2019
| | |

In the above table, the APAR links will provide more information about the fix.

Workarounds and Mitigations

None