Lucene search

K
ibmIBM99F64D98F690693F39DF61C96D664A3E7AF1C0DB6275BB60AE89164876A62084
HistoryAug 01, 2023 - 7:11 a.m.

Security Bulletin: Vulnerability in Rational Change 5.3.2 Fix Pack 05 and earlier versions.

2023-08-0107:11:26
www.ibm.com
12
rational change
apache commons fileupload
vulnerability
upgrade
denial of service

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.034 Low

EPSS

Percentile

91.4%

Summary

Vulnerability in the Apache Commons FileUpload before 1.5 and earlier component shipped with Rational Change may affect the security of the product.

Vulnerability Details

CVEID:CVE-2023-24998
**DESCRIPTION:**Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by not limit the number of request parts to be processed in the file upload function. By sending a specially-crafted request with series of uploads, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/247895 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Rational Change 5.3.2.5

Remediation/Fixes

Product VRFM APAR Remediation/Fix
Rational Change 5.3.2.6 None.

Upgrade to Rational Change 5.3.2.6 supporting Apache Commons FileUpload 1.5 from IBM Passport Advantage and apply it.

NOTE:

Download the Rational Change 5.3.2.6 installation image by referring to the installation platform and its part number in the following list:

  • IBM Rational Change V5.3.2.6 Multi-platform Multilingual (CC5T0ML) - Windows and Linux included.

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmrational_changeMatch5.3.2.5
CPENameOperatorVersion
rational changeeq5.3.2.5

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.034 Low

EPSS

Percentile

91.4%