Vulnerability Bulletins

IBM Security Bulletin: Open Source Apache Tomcat prior to 6.0.42 as used in IBM QRadar Security Information and Event Manager 7.1 MR2, and 7.2.4 is vulnerable to HTTP request smuggling. (CVE-2014-0227

   
Affected software IBM
 
Apache Tomcat prior to 6.0.43 is vulnerable to HTTP request smuggling. (CVE-2014-0227) CVE(s): CVE-2014-0227 Affected product(s) and affected version(s): IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 10 and prior. IBM QRadar Security Information and Event Manager 7.2.4 Patch 5 iFix 3 and prior. Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21959999

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_open_source_apache_tomcat_prior_to_6_0_42_as_used_in_ibm_qradar_security_information_and_event_manager_7_1_mr2_and_7_2_4_is_vulnerable_to_http_request_smuggling_cve_2014_0227