IBM Integration Bus is affected by an Apache Tomcat related vulnerability (CVE-2017-7674).
CVEID:CVE-2017-7674**
DESCRIPTION: *Apache Tomcat could provide weaker than expected security, caused by the failure to add an HTTP Vary header to indicate that the response varies depending on Origin by the CORS Filter. A remote attacker could exploit this vulnerability to conduct client and server side cache poisoning.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/130248 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
IBM Integration Bus V9.0.0.0 - V9.0.0.8 and V10.0.0.0 - V10.0.0.9
Product
|
VRMF
|
APAR
|
Remediation / Fix
—|—|—|—
IBM Integration Bus| V10.0.0.0 to V10.0.0.9| IT22859 | The APAR is available in fix pack v10.0.0.10
<http://www-01.ibm.com/support/docview.wss?uid=swg24043943>
IBM Integration Bus| V9.0.0.0 to V9.0.0.8| IT22859 | The APAR is available in fix pack v9.0.0.9
<http://www-01.ibm.com/support/docview.wss?uid=swg24043947>
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm integration bus | eq | 10.0 | |
ibm integration bus | eq | 9.0 |