Lucene search

K
ibmIBM788251FD7397EDDA8B4E4DF8AACBE1D142303877A23213E980EDE042998B46CF
HistoryMar 23, 2022 - 10:07 p.m.

Security Bulletin: Vulnerabilities in IBM WebSphere Application Server Liberty affect BM Spectrum Control (CVE-2019-17573, CVE-2019-12406)

2022-03-2322:07:22
www.ibm.com
19
ibm websphere application server liberty
ibm spectrum control
apache cxf
cross-site scripting
denial of service
cve-2019-17573
cve-2019-12406
ibm spectrum control 5.3.0 - 5.3.6 fix

EPSS

0.016

Percentile

87.4%

Summary

IBM WebSphere Application Server Liberty is vulnerable to Apache CXF cross-site scripting and denial of service . These vulnerabilities affect IBM Spectrum Control.

Vulnerability Details

CVEID:CVE-2019-17573
**DESCRIPTION:**Apache CXF is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the services listing page. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174689 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

CVEID:CVE-2019-12406
**DESCRIPTION:**Apache CXF is vulnerable to a denial of service, caused by the failure to restrict the number of message attachments present in a given message. By sending a specially-crafted message containing an overly large number of message attachments, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/170974 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Control 5.3.0 - 5.3.6

Remediation/Fixes

The solution is to apply an appropriate IBM Spectrum Control fix. Click on the download link and follow the Installation Instructions. The solution should be implemented as soon as practicable.

Release First Fixing VRM Level ** Link to Fix**
5.3 5.3.7 <http://www.ibm.com/support/docview.wss?uid=swg21320822#53_0&gt;

Workarounds and Mitigations

None

EPSS

0.016

Percentile

87.4%

Related for 788251FD7397EDDA8B4E4DF8AACBE1D142303877A23213E980EDE042998B46CF