Lucene search

K
ibmIBMD4D59CFE21484F96852DB1D04961FBD5D11A6439B4EFDD7D5412D5A9FFAD9732
HistoryApr 19, 2021 - 9:38 p.m.

Security Bulletin: Resilient OnPrem versions 30.x are affected by vulnerabilities in dependent libraries

2021-04-1921:38:35
www.ibm.com
13
resilient onprem
v31.0
vulnerabilities
dependent libraries
jetty
timing channel
http request smuggling
cve-2017-9735
cve-2017-7658

EPSS

0.011

Percentile

84.6%

Summary

Security Bulletin: Resilient OnPrem versions 30.x are affected by vulnerabilities in dependent libraries

Vulnerability Details

SummaryResilient OnPrem v31.0 has addressed vulnerabilities in a number of dependent libraries.

Vulnerability Details

CVEID:CVE-2017-9735
**DESCRIPTION:*Jetty could allow a remote attacker to obtain sensitive information, caused by a timing channel flaw in util/security/Password.java. By observing elapsed times before rejection of incorrect passwords, an attacker could exploit this vulnerability to obtain access information.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/127842&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2017-7658
**DESCRIPTION:**Eclipse Jetty is vulnerable to HTTP request smuggling, caused by a flaw when handling more than one Content-Length headers. By sending a specially-crafted request, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabi