Lucene search

K
ibmIBMFB20F052B3970A92A99B5F6099486D3A517E17CC9E48FB0EDC62029830F2CAC6
HistoryJul 18, 2019 - 9:05 a.m.

Security Bulletin: A vulnerability in IBM WebSphere Application Server affects IBM Spectrum Scale packaged in IBM Elastic Storage Server (CVE-2019-4046)

2019-07-1809:05:01
www.ibm.com
13

EPSS

0.005

Percentile

76.0%

Summary

There is a vulnerability in IBM WebSphere Application Server, used by IBM Spectrum Scale. This issue allows a remote attacker to cause a denial of service condition.

Vulnerability Details

CVEID: CVE-2019-4046 DESCRIPTION: IBM WebSphere Application Server is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory.
CVSS Base Score: 5.9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156242&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS: 3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

The Elastic Storage Server 5.3.0 thru 5.3.3
The Elastic Storage Server 5.0.0 thru 5.2.6
The Elastic Storage Server 4.5.0 thru 4.6.0
The Elastic Storage Server 4.0.0 thru 4.0.6

Remediation/Fixes

For IBM Elastic Storage Server V5.0.0 thru 5.3.3, apply V5.3.4 available from FixCentral at:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Elastic+Storage+Server+(ESS)&release=5.3.0&platform=All&function=all

For IBM Elastic Storage Server V5.0.0 thru 5.2.6, apply V5.2.7 available from FixCentral at:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Elastic+Storage+Server+(ESS)&release=5.2.0&platform=All&function=all

If you are unable to upgrade to ESS 5.3.4 or 5.2.7, contact IBM Service to obtain an efix:

- For IBM Elastic Storage Server 5.3.0-5.3.3, reference APAR IJ15943
- For IBM Elastic Storage Server 5.0.0- 5.2.6, reference APAR IJ15977
- For IBM Elastic Storage Server 4.0.0 - 4.6.0, reference APAR IJ15977

To contact IBM Service, see <http://www.ibm.com/planetwide/&gt;

Workarounds and Mitigations

None

EPSS

0.005

Percentile

76.0%

Related for FB20F052B3970A92A99B5F6099486D3A517E17CC9E48FB0EDC62029830F2CAC6