Lucene search

K
ibmIBM57F39E8955BA020FA3894E7D97096A08A62E0DBD4552788AC0264C2C0A3680A4
HistoryJun 16, 2018 - 7:43 p.m.

Security Bulletin: IBM Tealeaf Customer Experience may be affected by a vulnerability in the Apache HTTP server (CVE-2014-0226).

2018-06-1619:43:49
www.ibm.com
10

0.957 High

EPSS

Percentile

99.4%

Summary

IBM Tealeaf Customer Experience may be affected by a vulnerability in the Apache HTTP server, caused by an error in the mod_status module.

Vulnerability Details

CVEID:_CVE-2014-0226 _

DESCRIPTION:

IBM Tealeaf Customer Experiences PCA uses the Apache HTTP server to render its web console. Apache HTTP Server is vulnerable to a heap-based buffer overflow, caused by an error in the mod_status module when handling the scoreboard. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/94678 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Affected Products and Versions

IBM Tealeaf Customer Experience : v8.0-v9.0.0

Remediation/Fixes

Customers can update the mod_status of the Apache server with the Apache provided fixes by following these steps:

  1. Apply the fix pack below.
  2. Edit the Apache server’s httpd.conf file for the PCA located in:
    <PCA base install directory>/etc/httpd.conf
  3. Locate the following conf line and delete it:
    LoadModule status_module libexec/mod_status.so
  4. Save the changes
  5. Restart the PCA web console by running the following command from the command shell:
    tealeaf restart httpd

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM Tealeaf Customer Experience

|

9.0.0, 9.0.0A

| You can contact the Technical Support team for guidance.

IBM Tealeaf Customer Experience

|

8.8

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.8_IBMTealeaf_PCA-3625-4_SecurityRollup_FixPack

IBM Tealeaf Customer Experience

|

8.7

| https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.7_IBMTealeaf_PCA-3615-4_SecurityRollup_FixPack

IBM Tealeaf Customer Experience

|

8.6 and earlier

| You can contact the Technical Support team for guidance.
For v9.0.0, 9.0.0A, and versions before v8.7, IBM recommends upgrading to a later supported version of the product.

Workarounds and Mitigations

The PCA web console’s Apache server remediation fix for the Apache HTTP Server mod_status buffer overflow vulnerability is to remove the loading of the mod_status module from the Apache server as it isnt needed by the PCA,

CPENameOperatorVersion
tealeaf customer experienceeqany