Lucene search

K
ibmIBMDD5BF5116E5741EB672335643731F4B54ACDBD92F34C019A128C14DD0EF87E44
HistoryNov 23, 2018 - 9:35 a.m.

Security Bulletin: Information disclosure in Apache Commons HttpClient used by WebSphere Application Server shipped with Tivoli Integrated Portal (CVE-2012-5783)

2018-11-2309:35:02
www.ibm.com
12

0.002 Low

EPSS

Percentile

62.1%

Summary

There is a potential information disclosure in Apache Commons HttpClient used by WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2012-5783 DESCRIPTION: Apache Commons HttpClient, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, could allow a remote attacker to conduct spoofing attacks, caused by the failure to verify that the server hostname matches a domain name in the subject’s Common Name (CN) field of the X.509 certificate. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/79984 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

Tivoli Integrated Portal version 2.1.0 - 2.1.0.5

Tivoli Integrated Portal version 2.2.0.0 - 2.2.0.19

Remediation/Fixes

Principal Product and Version(s) Affected Supporting Product and Version Affected Supporting Product Security Bulletin
Tivoli Integrated Portal version

2.1.0 - 2.1.0.5

2.2.0 - 2.2.0.19

| embedded Websphere Application Server version 7.0.x |

Security Bulletin: Information disclosure in Apache Commons HttpClient used by WebSphere Application Server (CVE-2012-5783)

The Websphere security bulletin above provides a link to the required iFix to remediate the vulnerability. However, the iFix requires either eWAS 7.0.0.31 or higher installed.

TIP does not support upgrading Websphere fixpack independently. TIP 2.2.0.15 or TIP 2.2.0.17 or TIP 2.2.0.19 must be applied which will upgrade eWAS to 7.0.0.31 and above. Once TIP FP has been applied, the Websphere iFix can be applied as described in the Websphere bulletin.

Workarounds and Mitigations

Please refer to WAS iFix as described above

CPENameOperatorVersion
tivoli integrated portaleqany