Lucene search

K
ibmIBMAC328B0BD7747247509DF824A76882A7ABF67BDC8C756027B0F8E60F14B5C2DD
HistoryJun 15, 2018 - 6:59 a.m.

Security Bulletin: IBM Support Assistant (CVE-2014-0050)

2018-06-1506:59:44
www.ibm.com
10

0.191 Low

EPSS

Percentile

96.3%

Summary

The IBM® Support Assistant Team Server is shipped with the Apache Commons FileUpload™ library which contains a security vulnerability which may lead to a denial of service against IBM Support Assistant Team Server.

Vulnerability Details

CVEID:_CVE-__2014-0050 _
DESCRIPTION:
Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by the improper handling of Content-Type HTTP header for multipart requests. By sending a specifically-crafted request, an attacker could exploit this vulnerability to cause the application to enter into an infinite loop.

CVSS Base Score: 5.0
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/90987 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:X/AC:X/Au:X/C:X/I:X/A:X)

Affected Products and Versions

IBM Support Assistant v5r0m0

Remediation/Fixes

Apply fixpack 5.0.1. See the fix pack announcement for more information.

Workarounds and Mitigations

none

CPENameOperatorVersion
ibm support assistanteq5.0