Lucene search

K
ibmIBMCED198976CBF7EBEDAC77130D4FA16AE957E3EC915EABEC76847598DF951D713
HistoryJun 17, 2018 - 4:55 a.m.

Security Bulletin: Open Source Apache HTTP vulnerabilities (CVE-2014-0098) for RAF

2018-06-1704:55:54
www.ibm.com
12

EPSS

0.224

Percentile

96.5%

Summary

Previous releases of IBM Rational Automation Framework (RAF) are affected by the vulnerabilitie in Apache HTTP Server that may allow remote attackers to influence the availability of the Framework Server.

Vulnerability Details

| Subscribe to My Notifications to be notified of important product support alerts like this.

  • Follow this link for more information (requires login with your IBM ID)
    β€”|β€”

CVE-ID:CVE-2014-0098

Description: Apache HTTP Server is vulnerable to a denial of service. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the service to crash.

CVSS Base Score: 5 **CVSS Temporal Score: **See <https://exchange.xforce.ibmcloud.com/vulnerabilities/91879&gt; for the current score. *CVSS Environmental Score:**Undefined **CVSS Vector: **(AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

Rational Automation Framework 3.0.1, 3.0.1.1 and 3.0.1.2 on all supported platforms.

Remediation/Fixes

For all affected versions of Rational Automation Framework_
_Upgrade to Rational Automation Framework version 3.0.1.2_iFix1 or later.

Workarounds and Mitigations

None