Lucene search

K
ibmIBM91C10A77460E47F53661352C6380E6E959F0A94B552C3AE3314BBEC480C0AD09
HistoryJul 19, 2020 - 12:49 a.m.

Security Bulletin: Security vulnerability in Apache HTTP affects IBM SmartCloud Entry (CVE-2017-9798)

2020-07-1900:49:12
www.ibm.com
20

EPSS

0.974

Percentile

99.9%

Summary

IBM SmartCloud Entry has addressed the vulnerability in Apache HTTP. Following are the vulnerability details.

Vulnerability Details

CVEID: CVE-2017-9798**
DESCRIPTION:** Apache HTTP Server could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/132159 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM Smart Cloud Entry 2.4, 3.1, and 3.2

Remediation/Fixes

Product

| VRMF|APAR|Remediation/First Fix
—|—|—|—
IBM SmartCloud Entry| 3.2| None| Contact IBM Support.
IBM SmartCloud Entry| 3.1| None
IBM SmartCloud Entry| 2.4| None

For all IBM Smart Cloud Entry releases, refer to information about the replacement program as per withdrawal announcement ENUS914-189. For information about the latest release of IBM Cloud Manager for Openstack, please see** **http://www-01.ibm.com/support/docview.wss?uid=isg400003605

Workarounds and Mitigations

None