Vulnerability Bulletins

Lotus Mashups is vulnerable to a denial of service

   
Affected software IBM
 
The version of Apache Commons upload used in Lotus Mashups is vulnerable to a denial of service through consumption of CPU resources. This can occur when Mashups ingests data from a document coming from an untrusted source. CVE(s): CVE-2014-0050 Affected product(s) and affected version(s): Lotus Mashups v2.0.0.2, Lotus Mashups v3,0,0,1 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/lotus_mashups_is_vulnerable_to_a_denial_of_service?lang=en_us