Lucene search

K
ibmIBME958100936EDC2D0333655BFE34E1B7F8D81CEDA480AF07C1DBCD19C65ABC6AD
HistoryOct 07, 2020 - 1:41 p.m.

Security Bulletin: App Connect Professional is affected by Apache Tomcat vulnerabilities.

2020-10-0713:41:00
www.ibm.com
12

0.002 Low

EPSS

Percentile

55.8%

Summary

App Connect Professional has addressed the following vulnerabilities reported in Apache Tomcat.

Vulnerability Details

CVEID:CVE-2020-11996
**DESCRIPTION:**Apache Tomcat is vulnerable to a denial of service. By sending a specially crafted sequence of HTTP/2 requests, a remote attacker could exploit this vulnerability to trigger high CPU usage for several seconds.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/184012 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

App Connect Professional v 7.5.3.0

Remediation/Fixes

Product VRMF APAR Remediation/First Fix
App Connect Professional 7.5.3.0 LI81678 7530 Fixcentral link

Workarounds and Mitigations

None

CPENameOperatorVersion
app connect professionaleq7.5.3