Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by the improper handling of Content-Type HTTP header for multipart requests. By sending a specially-crafted request, an attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
CVE ID:CVE-2014-050
CVSS Base Score: 5
CVSS Temporal Score: 3.9 See <https://exchange.xforce.ibmcloud.com/vulnerabilities/90987>
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)
Affected releases/versions/platforms:
-DataQuant V1.2 Fix Pack 19 (and lower)
-DataQuant V2.1 Fix Pack 1 (and lower)
The recommended solution is to install either:
-DataQuant V1.2 Fix Pack 20
-DataQuant V2.1 Fix Pack 2
both available for download from IBM Fix Central.
**Important note:**IBM strongly suggests that all System z customers be subscribed to the System z Security Portal to receive the latest critical System z security and integrity service. If you are not subscribed, see the instructions on the System z Security web site. Security and integrity APARs and associated fixes will be posted to this portal. IBM suggests reviewing the CVSS scores and applying all security or integrity fixes as soon as possible to minimize any potential risk.
None known.
CPE | Name | Operator | Version |
---|---|---|---|
ibm db2 administration tool for z/os | eq | 2.1.0 | |
ibm db2 administration tool for z/os | eq | 1.2.0 | |
ibm dataquant for z/os | eq | any |