Lucene search

K
ibmIBMEC44FB8E43A4ACE3E70572A9C176DA90A44A471EC4871646DA9BC2ADBCD35F57
HistoryJul 27, 2020 - 7:17 a.m.

Security Bulletin: Rational Build Forge Security Advisory for Apache HTTP Server (CVE-2020-1927, CVE-2020-1934)

2020-07-2707:17:02
www.ibm.com
32

0.003 Low

EPSS

Percentile

65.8%

Summary

There are multiple vulnerabilities in Apache HTTP Server affecting IBM Rational Build Forge.

Vulnerability Details

CVEID: CVE-2020-1927 DESCRIPTION: Apache HTTP Server could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the mod_rewrite module. An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites. CVSS Base score: 7.4 CVSS Temporal Score: See: <https://exchange.xforce.ibmcloud.com/vulnerabilities/178936&gt; for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)

CVEID: CVE-2020-1934 DESCRIPTION: Apache HTTP Server could allow a remote attacker to execute arbitrary code on the system, caused by the use of uninitialized value in mod_proxy_ftp. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system. CVSS Base score: 8.1 CVSS Temporal Score: See: <https://exchange.xforce.ibmcloud.com/vulnerabilities/172618&gt; for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
BuildForge 8.0 to 8.0.0.15

Remediation/Fixes

Apply the correct fix pack or iFix for your version of Build Forge:

Affected Version(s) Fix
Build Forge 8.0 to 8.0.0.15 Rational Build Forge 8.0.0.16 Download.

Workarounds and Mitigations

None