Lucene search

K
ibmIBM656B919C7F6F4FC9EB942A5DD6E224D96EADBA68910167DD2D2F9840D7E57BF3
HistoryDec 20, 2022 - 7:07 a.m.

Security Bulletin: IBM UrbanCode Build is affected by CVE-2021-43980

2022-12-2007:07:06
www.ibm.com
11
ibm urbancode build
cve-2021-43980
apache tomcat vulnerability
upgrade
download
tomcat 8.5.84

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

58.5%

Summary

IBM UrbanCode Build is affected by CVE-2021-43980

Vulnerability Details

CVEID:CVE-2021-43980
**DESCRIPTION:**Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by a long standing concurrency flaw in the simplified implementation of blocking reads and writes. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain Http11Processor instance information, and use this information to launch further attacks against the affected system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/237447 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM UrbanCode Build 6.1.4.0-6.1.7.6

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading to IBM UrbanCode Build version 6.1.7.7 or above.

Affected Supporting Product(s) Remediation/Fix
IBM UrbanCode Build 6.1.4.0 - 6.1.7.6 Download IBM UrbanCode Build 6.1.7.7 – Includes Tomcat 8.5.84

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmrational_clearquestMatch6.1.4
OR
ibmrational_clearquestMatch6.1.7.7
CPENameOperatorVersion
rationaleq6.1.4
rationaleq6.1.7.7

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

0.002 Low

EPSS

Percentile

58.5%